
Website statistics with Matomo Security & Risk Analysis
wordpress.org/plugins/webstats-matomoIntegration of statistics provided by Matomo for WordPress.
Is Website statistics with Matomo Safe to Use in 2026?
Generally Safe
Score 100/100Website statistics with Matomo has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The webstats-matomo plugin v1.28 presents a mixed security profile. On the positive side, there are no identified CVEs in its history, suggesting a history of relative stability and prompt patching if issues have arisen. The static analysis also indicates a lack of dangerous functions and a commitment to prepared statements for all SQL queries, which are excellent security practices.
However, several concerning signals emerge from the static analysis. The presence of a flow with an unsanitized path in the taint analysis, even without a critical or high severity rating, warrants attention as it indicates a potential vector for path traversal or file inclusion vulnerabilities if exploited. Furthermore, a very low percentage of properly escaped output (17%) is a significant concern, as it exposes the plugin to cross-site scripting (XSS) vulnerabilities if user-supplied data is not properly sanitized before being displayed to users. The absence of nonce and capability checks on the identified entry points, though the attack surface appears minimal, also leaves room for potential unauthorized actions or information disclosure in specific scenarios.
In conclusion, while the plugin benefits from a clean vulnerability history and secure SQL handling, the high proportion of unescaped output and the identified unsanitized path flow represent notable weaknesses. These areas should be prioritized for immediate review and remediation to strengthen the plugin's overall security posture and mitigate potential risks.
Key Concerns
- Unsanitized path flow identified
- Low percentage of properly escaped output
- No nonce checks on entry points
- No capability checks on entry points
Website statistics with Matomo Security Vulnerabilities
Website statistics with Matomo Release Timeline
Website statistics with Matomo Code Analysis
Output Escaping
Data Flow Analysis
Website statistics with Matomo Attack Surface
WordPress Hooks 7
Maintenance & Trust
Website statistics with Matomo Maintenance & Trust
Maintenance Signals
Community Trust
Website statistics with Matomo Alternatives
GA Google Analytics – Connect Google Analytics to WordPress
ga-google-analytics
Adds Google Analytics tracking code to your WordPress site. Supports many tracking features.
Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative)
burst-statistics
Analytics you'll actually use. Privacy-friendly, zero config, and designed to be actionable. Get insights, not just raw data.
Post Views Counter
post-views-counter
Post Views Counter allows you to collect and display how many times a post, page, or other content has been viewed in a simple, fast and reliable way.
Independent Analytics
independent-analytics
A simple WordPress analytics plugin that is privacy-friendly, fast, and an alternative to Google Analytics.
Statify
statify
Visitor statistics for WordPress with focus on data protection, transparency and clarity. Perfect as a widget in your WordPress Dashboard.
Website statistics with Matomo Developer Profile
5 plugins · 29K total installs
How We Detect Website statistics with Matomo
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/webstats-matomo/proxy/matomo.php/wp-content/plugins/webstats-matomo/proxy/matomo.phpwebstats-matomo/style.css?ver=HTML / DOM Fingerprints
wsm_textidSitematomoTrackingApiUrl_paq