
Visitor Traffic Real Time Statistics Security & Risk Analysis
wordpress.org/plugins/visitors-traffic-real-time-statisticsThis plugin will help you to track your visitors, browsers, operating systems, visits and much more in one dashboard page.
Is Visitor Traffic Real Time Statistics Safe to Use in 2026?
Generally Safe
Score 97/100Visitor Traffic Real Time Statistics has a strong security track record. Known vulnerabilities have been patched promptly.
The "visitors-traffic-real-time-statistics" plugin exhibits a mixed security posture. While it demonstrates good practices in SQL query handling (94% prepared statements) and output escaping (79%), significant concerns arise from its attack surface and historical vulnerability patterns. The presence of 4 unprotected AJAX handlers and 3 taint flows with unsanitized paths are critical weaknesses that could be exploited by attackers. The plugin's history of 7 known CVEs, with 5 high and 2 medium severity vulnerabilities, strongly indicates a recurring pattern of security oversights, particularly related to authorization and SQL injection. Although there are currently no unpatched vulnerabilities, this history suggests a potential for future exploits if these underlying issues are not addressed comprehensively. The bundled libraries, DataTables and Select2, could also pose a risk if they are outdated and contain known vulnerabilities.
Key Concerns
- Unprotected AJAX handlers
- High severity taint flows
- Bundled libraries
- Vulnerability history (high severity)
- Vulnerability history (medium severity)
Visitor Traffic Real Time Statistics Security Vulnerabilities
CVEs by Year
Severity Breakdown
7 total CVEs
Visitors Traffic Real Time Statistics <= 7.2 - Missing Authorization via multiple AJAX actions
Visitor Traffic Real Time Statistics <= 6.7 - Missing Authorization to Information Disclosure
Visitor Traffic Real Time Statistics <= 3.8 - Subscriber+ SQL Injection
Visitor Traffic Real Time Statistics <= 2.11 - Missing Authorization to Arbitrary Plugin Installation/Activation
Visitor Traffic Real Time Statistics <= 2.13 - Cross-Site Request Forgery to Arbitrary Plugin Installation/Activation
Visitor Traffic Real Time Statistics <= 1.12 - Cross-Site Request Forgery
Visitor Traffic Real Time Statistics <= 1.13 - Cross-Site Request Forgery
Visitor Traffic Real Time Statistics Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Visitor Traffic Real Time Statistics Attack Surface
AJAX Handlers 11
Shortcodes 7
WordPress Hooks 31
Scheduled Events 1
Maintenance & Trust
Visitor Traffic Real Time Statistics Maintenance & Trust
Maintenance Signals
Community Trust
Visitor Traffic Real Time Statistics Alternatives
WPS Visitor Counter
wps-visitor-counter
Display website visitor statistics with widget, shortcode, and Gutenberg block support.
Mechanic Visitor Counter
mechanic-visitor-counter
Mechanic Visitor Counter is a widgets which will display the Visitor counter and traffic statistics on WordPress. Some of the features offered include …
XT Visitor Counter
xt-visitor-counter
XT Visitor Counter is a widgets which will display the Visitor counter and traffic statistics on WordPress. Some of the features offered include Today …
WP Post Statistics (Visitors & Visits Counter)
wp-post-real-time-statistics
a simple tool to know your post statistics
Total Views
total-views
Count total page views on your WordPress site and display them with a simple shortcode. Customizable label, styles, and editable page views.
Visitor Traffic Real Time Statistics Developer Profile
13 plugins · 355K total installs
How We Detect Visitor Traffic Real Time Statistics
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/visitors-traffic-real-time-statistics/assets/css/heatmap.css/wp-content/plugins/visitors-traffic-real-time-statistics/assets/css/style.css/wp-content/plugins/visitors-traffic-real-time-statistics/assets/js/chart.min.js/wp-content/plugins/visitors-traffic-real-time-statistics/assets/js/data.js/wp-content/plugins/visitors-traffic-real-time-statistics/assets/js/dashboard.js/wp-content/plugins/visitors-traffic-real-time-statistics/assets/js/ heatmap.js/wp-content/plugins/visitors-traffic-real-time-statistics/assets/js/users.js/wp-content/plugins/visitors-traffic-real-time-statistics/assets/js/chart.min.js/wp-content/plugins/visitors-traffic-real-time-statistics/assets/js/data.js/wp-content/plugins/visitors-traffic-real-time-statistics/assets/js/dashboard.js/wp-content/plugins/visitors-traffic-real-time-statistics/assets/js/ heatmap.js/wp-content/plugins/visitors-traffic-real-time-statistics/assets/js/users.jsvisitors-traffic-real-time-statistics/assets/css/heatmap.css?ver=visitors-traffic-real-time-statistics/assets/css/style.css?ver=visitors-traffic-real-time-statistics/assets/js/chart.min.js?ver=visitors-traffic-real-time-statistics/assets/js/data.js?ver=visitors-traffic-real-time-statistics/assets/js/dashboard.js?ver=visitors-traffic-real-time-statistics/assets/js/ heatmap.js?ver=visitors-traffic-real-time-statistics/assets/js/users.js?ver=HTML / DOM Fingerprints
vtrts-admin-chart-wrapper<!-- admin bar --><!-- admin bar for footer -->vtrts_chart_datavtrts_users_datavtrts_free_adminbar_chart/wp-json/vtrts/v1/visitors/online