
Simple Statistics for Feeds Security & Risk Analysis
wordpress.org/plugins/simple-feed-statsTracks your feeds and displays your feed count via shortcode.
Is Simple Statistics for Feeds Safe to Use in 2026?
Generally Safe
Score 99/100Simple Statistics for Feeds has a strong security track record. Known vulnerabilities have been patched promptly.
The "simple-feed-stats" plugin v20260202 exhibits a mixed security posture. On the positive side, it demonstrates good practices by having no unauthenticated AJAX handlers or REST API routes, and it includes a reasonable number of nonce and capability checks. The absence of file operations and external HTTP requests further reduces its attack surface. However, there are areas of concern, particularly in its handling of SQL queries and output escaping. While the majority of SQL queries use prepared statements, a significant percentage do not, posing a potential risk for SQL injection vulnerabilities. Similarly, the 74% proper output escaping rate means that a notable portion of outputs are not adequately sanitized, potentially leading to Cross-Site Scripting (XSS) vulnerabilities.
The taint analysis reveals one flow with an unsanitized path, which is flagged as high severity. This is a critical indicator of a potential vulnerability that could be exploited if an attacker can control input leading to this unsanitized path. The vulnerability history shows one medium severity CVE for Cross-Site Request Forgery (CSRF) in the past, which, while currently patched, suggests a pattern of past security weaknesses that require ongoing vigilance. The plugin is currently free of unpatched CVEs, which is a positive sign, but the past medium severity CSRF vulnerability combined with the high-severity taint flow warrants careful consideration.
In conclusion, while "simple-feed-stats" has strengths in its limited external interactions and its efforts to secure entry points, the presence of unsanitized paths in taint analysis and a history of past vulnerabilities, coupled with less than ideal SQL and output sanitization, indicate that this plugin is not entirely without risk. Continued monitoring and development focusing on hardening the sanitization of SQL queries and all output will be crucial for maintaining a secure environment.
Key Concerns
- High severity taint flow with unsanitized path
- SQL queries not using prepared statements (42%)
- Output escaping not properly handled (26%)
- Past medium severity CVE (CSRF)
Simple Statistics for Feeds Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Simple Statistics for Feeds <= 20250322 - Cross-Site Request Forgery
Simple Statistics for Feeds Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Simple Statistics for Feeds Attack Surface
Shortcodes 5
WordPress Hooks 28
Scheduled Events 2
Maintenance & Trust
Simple Statistics for Feeds Maintenance & Trust
Maintenance Signals
Community Trust
Simple Statistics for Feeds Alternatives
Cartograf Featured-image in Feed
cartograf-featured-image-in-feed
Includes the featured image of a post at the beginning of the item's content in the WordPress generated feeds. With this plugin, you no longer ne …
Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative)
burst-statistics
Analytics you'll actually use. Privacy-friendly, zero config, and designed to be actionable. Get insights, not just raw data.
Statify
statify
Visitor statistics for WordPress with focus on data protection, transparency and clarity. Perfect as a widget in your WordPress Dashboard.
StatCounter – Free Real Time Visitor Stats
official-statcounter-plugin-for-wordpress
StatCounter.com powered real-time detailed stats about the visitors to your blog.
Koko Analytics – Privacy Friendly Statistics for WordPress
koko-analytics
Koko Analytics is a privacy-friendly statistics plugin for WordPress that is an easy to use alternative to Google Analytics.
Simple Statistics for Feeds Developer Profile
30 plugins · 1.2M total installs
How We Detect Simple Statistics for Feeds
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/simple-feed-stats/HTML / DOM Fingerprints
sfs-widgetsfs-feed-statsdata-sfs-feeddata-sfs-idsfs_feed_data[simple_feed_stats[sfs_stats