StatPress Dashboard Widget Lite Security & Risk Analysis

wordpress.org/plugins/statpress-dashboard-widget-lite

Real time stats from StatPress for your Wordpress Dashboard - Lite-Version

200 active installs v2.0 PHP + WP 2.9.2+ Updated Jan 4, 2011
counterdashboardstatpresswidget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is StatPress Dashboard Widget Lite Safe to Use in 2026?

Generally Safe

Score 85/100

StatPress Dashboard Widget Lite has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 15yr ago
Risk Assessment

The StatPress Dashboard Widget Lite plugin exhibits a strong security posture regarding its attack surface. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, which significantly limits potential entry points for attackers. The absence of external HTTP requests and file operations further contributes to this robust defense. However, the code analysis reveals significant concerns in how data is handled. A substantial number of SQL queries are present, and alarmingly, none of them utilize prepared statements. This lack of sanitization makes the plugin highly susceptible to SQL injection vulnerabilities, especially if any of the data processed by these queries originates from user input. Furthermore, a large percentage of output escaping is not properly implemented, indicating potential cross-site scripting (XSS) vulnerabilities where unsanitized data could be injected and executed in a user's browser. The plugin's vulnerability history is clean, with no known CVEs. This suggests that either the plugin has been developed with a high degree of care or that its limited functionality and attack surface have not yet attracted significant security scrutiny or exploit development. While the lack of known vulnerabilities is positive, the identified coding practices in SQL query handling and output escaping present a clear and present danger that must be addressed.

Key Concerns

  • SQL queries lack prepared statements
  • Output escaping is not properly implemented
  • No capability checks on entry points
  • No nonce checks on entry points
Vulnerabilities
None known

StatPress Dashboard Widget Lite Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

StatPress Dashboard Widget Lite Code Analysis

Dangerous Functions
0
Raw SQL Queries
14
0 prepared
Unescaped Output
18
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared14 total queries

Output Escaping

0% escaped18 total outputs
Attack Surface

StatPress Dashboard Widget Lite Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionwp_dashboard_setupstatpress-dashboard-widget.php:230
Maintenance & Trust

StatPress Dashboard Widget Lite Maintenance & Trust

Maintenance Signals

WordPress version tested3.1.4
Last updatedJan 4, 2011
PHP min version
Downloads22K

Community Trust

Rating0/100
Number of ratings0
Active installs200
Developer Profile

StatPress Dashboard Widget Lite Developer Profile

Dunkelwesen

1 plugin · 200 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect StatPress Dashboard Widget Lite

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
widefat
FAQ

Frequently Asked Questions about StatPress Dashboard Widget Lite