StatsTracker – Download Status Viewer Security & Risk Analysis
wordpress.org/plugins/statstracker-download-status-viewerView download status and basic statistics for selected WordPress.org plugins directly from your dashboard or frontend.
Is StatsTracker – Download Status Viewer Safe to Use in 2026?
Generally Safe
Score 100/100StatsTracker – Download Status Viewer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The security posture of the 'statstracker-download-status-viewer' plugin version 1.0 appears to be strong based on the provided static analysis. The absence of dangerous functions, SQL injection vulnerabilities (all queries use prepared statements), and proper output escaping across all outputs are significant strengths. File operations and external HTTP requests are also not present or appear to be handled securely, and the plugin utilizes nonce checks. The vulnerability history is also clean, with no recorded CVEs, which suggests a good track record for security. However, a notable concern is the complete lack of capability checks. This means that any user, regardless of their role or permissions, could potentially interact with the plugin's functionality, including its single shortcode. While the attack surface is small and there are no unprotected AJAX handlers or REST API routes, the absence of role-based access control is a significant weakness that could be exploited if the shortcode's functionality is sensitive.
Despite the clean vulnerability history and good coding practices in many areas, the lack of capability checks creates a potential avenue for privilege escalation or unauthorized access to plugin features. The static analysis did not reveal any critical or high severity issues in taint analysis, nor did it identify any unsanitized paths. The plugin's minimal attack surface (only one shortcode) is a positive, but this is overshadowed by the lack of granular access control. The plugin is therefore considered reasonably secure for general use, but administrators should be aware of the potential for unauthorized access to its features due to the absence of capability checks.
Key Concerns
- No capability checks present
StatsTracker – Download Status Viewer Security Vulnerabilities
StatsTracker – Download Status Viewer Release Timeline
StatsTracker – Download Status Viewer Code Analysis
Output Escaping
StatsTracker – Download Status Viewer Attack Surface
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
StatsTracker – Download Status Viewer Maintenance & Trust
Maintenance Signals
Community Trust
StatsTracker – Download Status Viewer Alternatives
EDD Metrics
edd-metrics
Better reports for Easy Digital Downloads, similar to Baremetrics.
Download Counter
download-counter
Counts the number of downloads for files and displays a table with the results.
Enhanced Ecommerce Plus for Easy Digital Downloads
enhanced-ecommerce-plus-easy-digital-downloads
Enhanced Ecommerce Tracking in Google Analytics for Easy Digital Downloads
Site Kit by Google – Analytics, Search Console, AdSense, Speed
google-site-kit
Site Kit is a one-stop solution for WordPress users to use everything Google has to offer to make them successful on the web.
MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy)
google-analytics-for-wordpress
The best free Google Analytics plugin for WordPress. See how visitors find and use your website so you can grow your business with powerful analytics.
StatsTracker – Download Status Viewer Developer Profile
23 plugins · 260 total installs
How We Detect StatsTracker – Download Status Viewer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/statstracker-download-status-viewer/assets/js/settings.js/wp-content/plugins/statstracker-download-status-viewer/assets/css/admin-settings.cssstatstracker-download-status-viewer/assets/js/settings.js?ver=statstracker-download-status-viewer/assets/css/admin-settings.css?ver=HTML / DOM Fingerprints
stdlstusvwr-new-slugstdlstusvwr-add-slugstdlstusvwr-slug-liststdlstusvwr-remove-slugid="stdlstusvwr-new-slug"id="stdlstusvwr-add-slug"id="stdlstusvwr-slug-list"id="stdlstusvwr-remove-slug"