
Redistats – Multisite stats Security & Risk Analysis
wordpress.org/plugins/redistatsWeb stats especially made for WordPress Multisite with a large number of blogs but also works on a single blog. No additional load on your server.
Is Redistats – Multisite stats Safe to Use in 2026?
Generally Safe
Score 85/100Redistats – Multisite stats has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of redistats v0.3 indicates a plugin with a seemingly minimal attack surface. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events exposed, which significantly reduces the opportunities for external attackers to interact with the plugin. Furthermore, the code signals show no dangerous functions, file operations, or external HTTP requests, and all SQL queries utilize prepared statements. This suggests a conscientious approach to core security practices within the plugin's current development.
However, a significant concern arises from the output escaping. With 9 total outputs and 0% properly escaped, this presents a clear and present risk of Cross-Site Scripting (XSS) vulnerabilities. Any data processed or displayed by the plugin, if not adequately sanitized before output, could be exploited by attackers to inject malicious scripts into web pages viewed by users. The absence of nonce checks and capability checks on potential entry points (though none are explicitly listed) also leaves room for potential authorization bypasses if any vulnerabilities are discovered in other areas. The lack of vulnerability history is positive but doesn't negate the inherent risks identified in the code itself.
In conclusion, while redistats v0.3 has a low attack surface and uses prepared statements for SQL, the complete lack of output escaping is a critical weakness. This makes the plugin highly susceptible to XSS attacks. The absence of any recorded vulnerabilities in its history is encouraging, but the current code analysis reveals a severe oversight that needs immediate attention to ensure user safety.
Key Concerns
- Unescaped output
- Missing nonce checks
- Missing capability checks
Redistats – Multisite stats Security Vulnerabilities
Redistats – Multisite stats Release Timeline
Redistats – Multisite stats Code Analysis
Output Escaping
Redistats – Multisite stats Attack Surface
WordPress Hooks 5
Maintenance & Trust
Redistats – Multisite stats Maintenance & Trust
Maintenance Signals
Community Trust
Redistats – Multisite stats Alternatives
Multisite Theme Statistics
wordpress-mu-theme-stats
Adds theme usage statistics within your network, shows themes by user and most popular themes.
Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative)
burst-statistics
Analytics you'll actually use. Privacy-friendly, zero config, and designed to be actionable. Get insights, not just raw data.
Statify
statify
Visitor statistics for WordPress with focus on data protection, transparency and clarity. Perfect as a widget in your WordPress Dashboard.
StatCounter – Free Real Time Visitor Stats
official-statcounter-plugin-for-wordpress
StatCounter.com powered real-time detailed stats about the visitors to your blog.
Koko Analytics – Privacy Friendly Statistics for WordPress
koko-analytics
Koko Analytics is a privacy-friendly statistics plugin for WordPress that is an easy to use alternative to Google Analytics.
Redistats – Multisite stats Developer Profile
1 plugin · 10 total installs
How We Detect Redistats – Multisite stats
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
redistats/icon.pngHTML / DOM Fingerprints
updatedRedistats, track version 1.0global_idproperty_id