
Posts and Users Stats Security & Risk Analysis
wordpress.org/plugins/posts-and-users-statsStatistics about the number of posts and users, provided as diagrams, tables and csv export.
Is Posts and Users Stats Safe to Use in 2026?
Generally Safe
Score 100/100Posts and Users Stats has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The plugin 'posts-and-users-stats' v1.1.4 exhibits a generally good security posture with several strengths. Notably, the absence of any detected AJAX handlers, REST API routes, shortcodes, or cron events without authentication checks significantly limits its attack surface. The code also demonstrates strong output escaping practices, with 100% of outputs being properly escaped, and a commendable 100% of SQL queries utilizing prepared statements. The presence of nonce and capability checks further indicates adherence to WordPress security best practices.
However, the static analysis did reveal a concerning taint analysis result: one flow with an unsanitized path. While the severity was not rated as critical or high, any unsanitized path represents a potential entry point for malicious data. Additionally, the vulnerability history shows one known medium-severity CVE related to improper neutralization of formula elements in a CSV file. While this vulnerability is currently patched, it highlights a past weakness in handling specific data types, which could be a recurring issue if not carefully managed.
In conclusion, the plugin has a solid foundation in secure coding practices, particularly in its handling of input and output. The limited attack surface and strong use of WordPress security features are commendable. The primary areas of concern stem from the single unsanitized taint flow and the past CSV vulnerability, suggesting a need for continued vigilance in data sanitization, especially when dealing with data that might be exported or processed in formats like CSV.
Key Concerns
- Taint flow with unsanitized path
- Past medium severity CVE
Posts and Users Stats Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Posts and Users Stats <= 1.1.3 - Authenticated (Subscriber+) CSV Injection
Posts and Users Stats Release Timeline
Posts and Users Stats Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Posts and Users Stats Attack Surface
WordPress Hooks 2
Maintenance & Trust
Posts and Users Stats Maintenance & Trust
Maintenance Signals
Community Trust
Posts and Users Stats Alternatives
Independent Analytics
independent-analytics
A simple WordPress analytics plugin that is privacy-friendly, fast, and an alternative to Google Analytics.
NewStatPress
newstatpress
NewStatPress (Statpress plugin fork) is a real-time plugin to manage the visits' statistics about your blog (without external web analytics).
Post Word Counter – Content Insights Dashboard
doubledome-wordcount-details-dashboard
The Word Counter plugin offers a dedicated dashboard view that tracks the word count, post count, pages wordcount, and custom post types across your e …
Access Watch: Security and Traffic Insights
access-watch
Understand precisely the robot traffic on your website and take actions to improve performance and security.
Plugin Name: CM Subscriber Stats
cm-subscriber-stats
See your email list subscriber statistics on your WordPress dashboard.
Posts and Users Stats Developer Profile
3 plugins · 21K total installs
How We Detect Posts and Users Stats
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/posts-and-users-stats/assets/style.min.css/wp-content/plugins/posts-and-users-stats/lib/chartist.min.css/wp-content/plugins/posts-and-users-stats/lib/chartist.min.js/wp-content/plugins/posts-and-users-stats/lib/chartist-plugin-axistitle.min.js/wp-content/plugins/posts-and-users-stats/lib/moment.min.js/wp-content/plugins/posts-and-users-stats/assets/functions.min.jsposts-and-users-stats/assets/style.min.css?ver=posts-and-users-stats/lib/chartist.min.css?ver=posts-and-users-stats/lib/chartist.min.js?ver=posts-and-users-stats/lib/chartist-plugin-axistitle.min.js?ver=posts-and-users-stats/lib/moment.min.js?ver=posts-and-users-stats/assets/functions.min.js?ver=HTML / DOM Fingerprints
nav-tabnav-tab-activeposts_and_users_stats_export_table_to_csv