TI Stat Security & Risk Analysis

wordpress.org/plugins/ti-stat

Plugins shows charts from Yandex.Metrika on page.

10 active installs v0.4 PHP + WP 2.8+ Updated Mar 2, 2012
metrikawidgetyandex
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is TI Stat Safe to Use in 2026?

Generally Safe

Score 85/100

TI Stat has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 14yr ago
Risk Assessment

The ti-stat plugin v0.4 exhibits a mixed security posture. On the positive side, it shows no known CVEs, no critical or high severity taint flows, and all SQL queries are properly prepared. It also demonstrates some security consciousness by including capability checks and a relatively small attack surface in terms of exposed entry points.

However, significant concerns arise from the static analysis. The complete lack of output escaping on all 65 detected outputs is a major weakness, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. The absence of nonce checks, especially given the presence of file operations and external HTTP requests, is another red flag, potentially opening avenues for Cross-Site Request Forgery (CSRF) or other injection attacks when combined with unescaped output.

While the plugin has no recorded vulnerability history, this does not guarantee its current security. The identified code signals strongly suggest exploitable weaknesses. The plugin has strengths in its lack of known vulnerabilities and secure SQL practices, but the critical deficiency in output sanitization and the absence of nonce checks present substantial risks that need immediate attention.

Key Concerns

  • 0% of outputs properly escaped
  • No nonce checks implemented
Vulnerabilities
None known

TI Stat Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

TI Stat Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
65
0 escaped
Nonce Checks
0
Capability Checks
1
File Operations
59
External Requests
4
Bundled Libraries
0

Output Escaping

0% escaped65 total outputs
Attack Surface

TI Stat Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[ystat] ti_stat.php:967
WordPress Hooks 4
actionadmin_initti_stat.php:975
actionplugins_loadedti_stat.php:1501
actionadmin_menuti_stat.php:1502
actionti_stat_daily_eventti_stat.php:1503

Scheduled Events 2

ti_stat_daily_event
ti_stat_daily_event
Maintenance & Trust

TI Stat Maintenance & Trust

Maintenance Signals

WordPress version tested3.2.1
Last updatedMar 2, 2012
PHP min version
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

TI Stat Developer Profile

TIgor4eg

3 plugins · 80 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect TI Stat

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
wrapform-table
Data Attributes
scope="row"
FAQ

Frequently Asked Questions about TI Stat