
Seraphinite Downloads Statistics Security & Risk Analysis
wordpress.org/plugins/seraphinite-downloads-statsMeasure direct downloads from your site.
Is Seraphinite Downloads Statistics Safe to Use in 2026?
Generally Safe
Score 100/100Seraphinite Downloads Statistics has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The Seraphinite Downloads Stats plugin version 1.3.1 presents a concerning security posture due to several critical vulnerabilities identified in the static analysis. The presence of two unprotected AJAX handlers represents a significant attack surface, as these can be exploited by unauthenticated users to execute arbitrary actions within the plugin. Furthermore, the extensive use of the `unserialize` function, coupled with a high percentage of unsanitized paths in taint analysis, strongly suggests potential for Remote Code Execution (RCE) or other severe attacks if user-controlled data is passed to these functions without proper validation and sanitization. The plugin also lacks essential security checks such as nonce and capability checks on its entry points, exacerbating the risk posed by the unprotected AJAX handlers. While there is no known vulnerability history, this should not be interpreted as a sign of robust security, but rather as a potential lack of historical auditing or discovery of existing issues. The plugin's strengths lie in its moderate use of prepared statements for SQL queries and a reasonable number of file operations and external HTTP requests, which are not inherently insecure. However, the identified vulnerabilities significantly outweigh these minor strengths, demanding immediate attention.
Key Concerns
- 2 AJAX handlers without auth checks
- Unsanitized paths in taint analysis (High severity)
- Use of 'unserialize' function
- No nonce checks
- No capability checks
- Low percentage of properly escaped output
Seraphinite Downloads Statistics Security Vulnerabilities
Seraphinite Downloads Statistics Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Seraphinite Downloads Statistics Attack Surface
AJAX Handlers 2
WordPress Hooks 38
Scheduled Events 1
Maintenance & Trust
Seraphinite Downloads Statistics Maintenance & Trust
Maintenance Signals
Community Trust
Seraphinite Downloads Statistics Alternatives
EDD Metrics
edd-metrics
Better reports for Easy Digital Downloads, similar to Baremetrics.
Download Counter
download-counter
Counts the number of downloads for files and displays a table with the results.
SFR Directory Analytics
sfr-directory-analytics
Free analytics for Directorist, GeoDirectory & Business Directory. Track listings, searches & performance with beautiful dashboards.
GA Google Analytics – Connect Google Analytics to WordPress
ga-google-analytics
Adds Google Analytics tracking code to your WordPress site. Supports many tracking features.
Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative)
burst-statistics
Analytics you'll actually use. Privacy-friendly, zero config, and designed to be actionable. Get insights, not just raw data.
Seraphinite Downloads Statistics Developer Profile
5 plugins · 61K total installs
How We Detect Seraphinite Downloads Statistics
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/seraphinite-downloads-stats/css/seraphinite-downloads-stats.css/wp-content/plugins/seraphinite-downloads-stats/js/seraphinite-downloads-stats.js/wp-content/plugins/seraphinite-downloads-stats/js/seraphinite-downloads-stats.jsseraphinite-downloads-stats/css/seraphinite-downloads-stats.css?ver=seraphinite-downloads-stats/js/seraphinite-downloads-stats.js?ver=HTML / DOM Fingerprints
seraphinite-downloads-stats-admin-wrapseraphinite-downloads-stats-admin-option-wrap<!-- Seraphinite Downloads Statistics -->data-seraphinite-downloads-stats-post-idseraphinite_downloads_stats