User stats WP Security & Risk Analysis

wordpress.org/plugins/user-stats-wp

Stores and displays user generated events, like logins and post edits.

0 active installs v1.0.0 PHP 7.2+ WP 5.2+ Updated Jul 28, 2021
analyticsstatisticsstatsuser
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is User stats WP Safe to Use in 2026?

Generally Safe

Score 85/100

User stats WP has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The "user-stats-wp" v1.0.0 plugin exhibits a strong security posture based on the provided static analysis. The absence of identified dangerous functions, raw SQL queries, unescaped output, file operations, external HTTP requests, and particularly the lack of any taint analysis findings suggest a well-written and secure codebase. The plugin also shows no recorded vulnerability history, further reinforcing its current security strength.

However, the analysis reveals a complete lack of security checks on its entry points. With zero AJAX handlers, REST API routes, shortcodes, and cron events, the plugin's attack surface is effectively zero. While this means there are no immediately exploitable vulnerabilities due to missing checks, it also means there are no authentication or authorization checks implemented at all. This absence of capability checks and nonce checks on potential entry points, if any were to be introduced in future versions, represents a significant oversight in standard WordPress security practices.

In conclusion, the plugin is currently secure due to its lack of functionality and therefore attack surface. The code itself appears to follow secure coding principles. The primary weakness lies in the absence of any security mechanisms, which, while not an issue now, could become a critical vulnerability if functionality is added without corresponding security controls. The bundled DataTables library also warrants attention for potential out-of-date issues.

Key Concerns

  • Bundled outdated library: DataTables v1.10.25
  • 0 Nonce checks on potential entry points
  • 0 Capability checks on potential entry points
Vulnerabilities
None known

User stats WP Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

User stats WP Release Timeline

No version history available.
Code Analysis
Analyzed Mar 17, 2026

User stats WP Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

DataTables1.10.25
Attack Surface

User stats WP Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionsave_postuser-stats-wp.php:42
actionadd_attachmentuser-stats-wp.php:43
Maintenance & Trust

User stats WP Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedJul 28, 2021
PHP min version7.2
Downloads873

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

User stats WP Developer Profile

Worbee Ltd

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect User stats WP

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/user-stats-wp/assets/css/backend.css/wp-content/plugins/user-stats-wp/assets/js/backend.js/wp-content/plugins/user-stats-wp/assets/css/frontend.css/wp-content/plugins/user-stats-wp/assets/js/frontend.js
Script Paths
/wp-content/plugins/user-stats-wp/assets/js/backend.js/wp-content/plugins/user-stats-wp/assets/js/frontend.js
Version Parameters
user-stats-wp/assets/css/backend.css?ver=user-stats-wp/assets/js/backend.js?ver=user-stats-wp/assets/css/frontend.css?ver=user-stats-wp/assets/js/frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
user-stats-wp-dashboard-wrapperuser-stats-wp-event-list
Data Attributes
data-user-stats-wp-nonce
JS Globals
userstatswpworbee
Shortcode Output
[user_stats_wp_dashboard][user_stats_wp_frontend]
FAQ

Frequently Asked Questions about User stats WP