
Post Volume Stats Security & Risk Analysis
wordpress.org/plugins/post-volume-statsShows stats for the volume of posts per year, month, day-of-the-month, day-of-the-week, hour-of-the-day, words per post, days between posts, author, c …
Is Post Volume Stats Safe to Use in 2026?
Generally Safe
Score 85/100Post Volume Stats has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "post-volume-stats" plugin v3.3.08 demonstrates a generally good security posture, particularly in its handling of entry points. All six identified AJAX handlers and the absence of REST API routes, shortcodes, or cron events indicate a well-controlled attack surface. The plugin also shows positive signs with the absence of dangerous functions, file operations, and external HTTP requests, all contributing to a reduced risk profile. The presence of nonce checks on all AJAX handlers is a crucial security measure that is correctly implemented.
However, there are areas for improvement. While the majority of SQL queries use prepared statements (59%), a significant portion do not, which could be a potential vector for SQL injection if these raw queries handle user-supplied input without proper sanitization. Similarly, with only 63% of outputs properly escaped, there is a risk of cross-site scripting (XSS) vulnerabilities if the remaining 37% are not handled carefully, especially if they involve user-generated content. The complete lack of capability checks on any of the entry points is a significant concern, meaning that unauthorized users could potentially trigger AJAX actions. The vulnerability history, showing no known CVEs, is reassuring but doesn't negate the importance of addressing the identified code-level weaknesses.
In conclusion, the plugin has strong foundational security practices, particularly in managing its entry points and avoiding common pitfalls like dangerous functions. The absence of critical taint flows and the robust use of prepared statements for SQL are commendable. Nevertheless, the lack of capability checks on AJAX handlers is a critical oversight that needs immediate attention. Addressing the remaining unescaped outputs and ensuring all SQL queries are properly sanitized, especially those not using prepared statements, will further strengthen its security.
Key Concerns
- Missing capability checks on entry points
- Significant portion of SQL queries without prepared statements
- Significant portion of outputs not properly escaped
Post Volume Stats Security Vulnerabilities
Post Volume Stats Release Timeline
Post Volume Stats Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Post Volume Stats Attack Surface
AJAX Handlers 6
WordPress Hooks 14
Maintenance & Trust
Post Volume Stats Maintenance & Trust
Maintenance Signals
Community Trust
Post Volume Stats Alternatives
Easy Chart Categories
easy-chart-categories
This is a WordPress plugin that provides a WordPress shortcode that will display your categories in a chart and another that will display your tags.
List category posts
list-category-posts
Very customizable plugin to list posts by category (or tag, author and more) in a post, page or widget. Uses the [catlist] shortcode to select posts.
Category Posts Widget
category-posts
Adds a widget that shows the most recent posts from a single category.
Visualizer: Tables and Charts Manager for WordPress
visualizer
Create responsive charts and tables manually or let the built-in AI build them from a simple text prompt. Supports multiple chart types and flexible d …
Essential Widgets
essential-widgets
Essential Widgets is a WordPress plugin for widgets that allows you to create and add amazing widgets with high customization option
Post Volume Stats Developer Profile
3 plugins · 200 total installs
How We Detect Post Volume Stats
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/post-volume-stats/sdpvs-admin.css/wp-content/plugins/post-volume-stats/sdpvs-admin.js/wp-content/plugins/post-volume-stats/sdpvs-frontend.js/wp-content/plugins/post-volume-stats/sdpvs-chart.jssdpvs-admin.jssdpvs-frontend.jssdpvs-chart.jspost-volume-stats/sdpvs-admin.css?ver=post-volume-stats/sdpvs-admin.js?ver=post-volume-stats/sdpvs-frontend.js?ver=post-volume-stats/sdpvs-chart.js?ver=HTML / DOM Fingerprints
sdpvsdata-sdpvs-categorydata-sdpvs-tagsdpvs_chart_datasdpvs_chart_options