
Stats for WP Security & Risk Analysis
wordpress.org/plugins/stats-for-wpWhen users view your site, we will log user ID, view pages, referrers URL, user IP, user agent, ... and so on, to admin you understand how users worki …
Is Stats for WP Safe to Use in 2026?
Generally Safe
Score 85/100Stats for WP has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "stats-for-wp" plugin v1.0.3 exhibits a generally good security posture based on the provided static analysis. The absence of identified dangerous functions, file operations, external HTTP requests, and a lack of identified critical or high-severity taint flows are positive indicators. The plugin also has a clean vulnerability history with no recorded CVEs, suggesting a history of responsible development and maintenance.
However, there are notable areas of concern. The complete lack of nonce checks and capability checks across all entry points (even though the attack surface is currently zero) presents a significant future risk. If any new entry points are introduced or if existing ones are modified without proper authentication and authorization mechanisms, they would be immediately exploitable. Furthermore, a low rate of proper output escaping (only 25%) indicates a potential for Cross-Site Scripting (XSS) vulnerabilities if any of the data being output is not sufficiently sanitized before display. The fact that 40% of SQL queries are not using prepared statements also raises concerns about potential SQL injection vulnerabilities, especially if user-supplied data can influence these queries.
In conclusion, while the plugin has avoided known vulnerabilities and has a minimal current attack surface, the foundational lack of security checks like nonces and capability checks, coupled with the high percentage of unescaped output and raw SQL queries, creates a latent risk. Future development or modifications need to address these critical security gaps proactively to maintain a secure state.
Key Concerns
- No Nonce Checks
- No Capability Checks
- Low Output Escaping Rate (25%)
- Unprepared SQL Queries (40%)
Stats for WP Security Vulnerabilities
Stats for WP Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Stats for WP Attack Surface
WordPress Hooks 2
Maintenance & Trust
Stats for WP Maintenance & Trust
Maintenance Signals
Community Trust
Stats for WP Alternatives
CP Referrer and Conversion Tracking
cp-referrer-and-conversions-tracking
CP Referrer and Conversion Tracking registers how the website visitors reached the website, identifying the referral website. Also track conversions.
PopStats
popstats
Popstats is a plugin to enhace statics of your blog, now you'll know more about your visitors.
WP Mail SMTP by WPForms – The Most Popular SMTP and Email Log Plugin
wp-mail-smtp
Make email delivery easy for WordPress. Connect with SMTP, Gmail, Outlook, SendGrid, Mailgun, SES, Zoho, + more. Rated #1 WordPress SMTP Email plugin.
WP Statistics – Simple, privacy-friendly Google Analytics alternative
wp-statistics
Get website traffic insights with GDPR/CCPA compliant, privacy-friendly analytics. Includes visitor data, stunning graphs, and no data sharing.
Easy WP SMTP – WordPress SMTP and Email Logs: Gmail, Office 365, Outlook, Custom SMTP, and more
easy-wp-smtp
Make SMTP email sending and delivery easy. Configure Gmail, Outlook, Brevo, SendGrid, Mailgun, SendLayer or connect to any SMTP server.
Stats for WP Developer Profile
1 plugin · 0 total installs
How We Detect Stats for WP
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/stats-for-wp/css/style.css/wp-content/plugins/stats-for-wp/js/sfw_stats_for_wp.jsstats-for-wp/css/style.css?ver=stats-for-wp/js/sfw_stats_for_wp.js?ver=HTML / DOM Fingerprints
wrapdashboard-widgets-wrapmetabox-holderdashboard-widgets-main-contentpostbox-containerpostboxbpmotableid="bpmotable"id="dashboard-widgets-wrap"id="dashboard-widgets"id="post-body"id="dashboard-widgets-main-content"