
Weblix – Online Users Security & Risk Analysis
wordpress.org/plugins/weblixDisplay online users and page views in the last 30 minutes, just like Google Analytics, but without slowing down your website.
Is Weblix – Online Users Safe to Use in 2026?
Generally Safe
Score 92/100Weblix – Online Users has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'weblix' v1.4.1 exhibits a generally strong security posture based on the static analysis provided. The plugin demonstrates good practices by employing prepared statements for nearly all SQL queries and properly escaping most output. It also has a very small attack surface with no unprotected entry points, no file operations, and no external HTTP requests. The absence of known vulnerabilities, including critical or high severity ones, further contributes to a positive security assessment.
However, there are a few areas that warrant attention. The lack of nonce checks across any of the entry points (AJAX handlers, REST API routes, or shortcodes, although none are directly exposed in this analysis) is a significant concern. While no critical taint flows were identified, the presence of capability checks on only 2 entry points suggests that the plugin might not be comprehensively protecting all sensitive actions from unauthorized access.
Overall, 'weblix' v1.4.1 appears to be a well-developed plugin from a security perspective, with a clean vulnerability history and good adherence to secure coding practices. The primary weakness lies in the absence of nonce checks, which, in conjunction with limited capability checks, could potentially expose the plugin to CSRF or unauthorized action vulnerabilities if the attack surface were to expand or be exploited in unexpected ways.
Key Concerns
- Missing nonce checks across entry points
- Limited capability checks on entry points
Weblix – Online Users Security Vulnerabilities
Weblix – Online Users Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Weblix – Online Users Attack Surface
REST API Routes 2
WordPress Hooks 8
Scheduled Events 1
Maintenance & Trust
Weblix – Online Users Maintenance & Trust
Maintenance Signals
Community Trust
Weblix – Online Users Alternatives
WP Statistics – Simple, privacy-friendly Google Analytics alternative
wp-statistics
Get website traffic insights with GDPR/CCPA compliant, privacy-friendly analytics. Includes visitor data, stunning graphs, and no data sharing.
WP Visitor Statistics (Real Time Traffic)
wp-stats-manager
This plugin will help you to track your visitors & visits, browsers, operating systems, GEO locations and much more, easy to install and working fine.
ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin)
google-analytics-dashboard-for-wp
Connects Google Analytics with your WordPress site. Displays stats to help you understand your users and site content on a whole new level!
Koko Analytics – Privacy Friendly Statistics for WordPress
koko-analytics
Koko Analytics is a privacy-friendly statistics plugin for WordPress that is an easy to use alternative to Google Analytics.
Fathom Analytics for WP
fathom-analytics
Fathom is a simple, GDPR compliant Google Analytics alternative.
Weblix – Online Users Developer Profile
1 plugin · 80 total installs
How We Detect Weblix – Online Users
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/weblix/assets/js/weblix-tracker.js/wp-content/plugins/weblix/assets/js/weblix-tracker.jstime()filemtime(HTML / DOM Fingerprints
data-weblix-user-ipdata-weblix-page-urldata-weblix-visit-timedata-weblix-device-typedata-weblix-page-titledata-weblix-is-botweblix_ajax/weblix/v1/track