
TI Stat Security & Risk Analysis
wordpress.org/plugins/ti-statPlugins shows charts from Yandex.Metrika on page.
Is TI Stat Safe to Use in 2026?
Generally Safe
Score 85/100TI Stat has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The ti-stat plugin v0.4 exhibits a mixed security posture. On the positive side, it shows no known CVEs, no critical or high severity taint flows, and all SQL queries are properly prepared. It also demonstrates some security consciousness by including capability checks and a relatively small attack surface in terms of exposed entry points.
However, significant concerns arise from the static analysis. The complete lack of output escaping on all 65 detected outputs is a major weakness, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. The absence of nonce checks, especially given the presence of file operations and external HTTP requests, is another red flag, potentially opening avenues for Cross-Site Request Forgery (CSRF) or other injection attacks when combined with unescaped output.
While the plugin has no recorded vulnerability history, this does not guarantee its current security. The identified code signals strongly suggest exploitable weaknesses. The plugin has strengths in its lack of known vulnerabilities and secure SQL practices, but the critical deficiency in output sanitization and the absence of nonce checks present substantial risks that need immediate attention.
Key Concerns
- 0% of outputs properly escaped
- No nonce checks implemented
TI Stat Security Vulnerabilities
TI Stat Code Analysis
Output Escaping
TI Stat Attack Surface
Shortcodes 1
WordPress Hooks 4
Scheduled Events 2
Maintenance & Trust
TI Stat Maintenance & Trust
Maintenance Signals
Community Trust
TI Stat Alternatives
Yandex Metrica
yandex-metrica
Easy way to use Yandex Metrica on your WordPress site.
Яндекс Метрика
yandex-metrika
Яндекс Метрика для вашего сайта на WordPress.
WT Yandex Metrika
wt-yandex-metrika
Простое добавление на сайт счетчика Яндекс.Метрика
DCO Insert Analytics Code
dco-insert-analytics-code
Allows you to insert analytics code before </head> or after <body> or before </body>
Simple Counter
abwp-simple-counter
The installation of the counter of Yandex.Metrics and Google Analytics on the website without editing the files of the selected theme.
TI Stat Developer Profile
3 plugins · 80 total installs
How We Detect TI Stat
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
wrapform-tablescope="row"