
Statistical Security & Risk Analysis
wordpress.org/plugins/statisticalA helpful, little plugin that shows useful, statistical information about the content on your blog, in a widget.
Is Statistical Safe to Use in 2026?
Generally Safe
Score 85/100Statistical has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "statistical" plugin v1.0a presents a mixed security posture. On the positive side, the static analysis reveals no identified dangerous functions, no file operations, no external HTTP requests, and 100% of SQL queries are using prepared statements, which are excellent security practices. Furthermore, there is no known vulnerability history for this plugin, suggesting a potentially clean track record. However, several areas raise significant concerns. The most notable issue is the extremely low percentage of properly escaped output (27%), indicating a high likelihood of cross-site scripting (XSS) vulnerabilities. Additionally, the complete absence of nonce checks and capability checks on any potential entry points, coupled with zero identified AJAX handlers, REST API routes, shortcodes, or cron events, is unusual and could imply a very limited attack surface, but also a lack of security controls where they might be expected. The lack of taint analysis flows is also a concern, as it's impossible to fully assess risks without this deeper examination, though the absence of critical/high severity flows is a positive sign.
Key Concerns
- Low output escaping percentage (27%)
- No nonce checks on potential entry points
- No capability checks on potential entry points
- Zero taint analysis flows analyzed
Statistical Security Vulnerabilities
Statistical Code Analysis
Output Escaping
Statistical Attack Surface
WordPress Hooks 6
Maintenance & Trust
Statistical Maintenance & Trust
Maintenance Signals
Community Trust
Statistical Alternatives
Search Meter
search-meter
Search Meter tracks what your readers are searching for on your site. View full details of recent searches or stats for the last day, week or month.
Statify Widget
statify-widget
Data privacy conform widget for list popular content (pages, posts, custom post types) – based on Statify plugin.
Contact Information Widget
contact-information-widget
Easily add a Contact Information Widget to your widgetable sidebar. With this plugin you can add a contact information.
Widget Contact Now
widget-contact-now
Add contact information quickly and easily with ready-made labels. Display gorgeous contact information on your website with simple, easy-to-use widge …
Contact Information Widget
simple-contact-information-widget
Contact Information Widget.
Statistical Developer Profile
1 plugin · 10 total installs
How We Detect Statistical
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
indefiniteloop-stats