Website statistics with Matomo Security & Risk Analysis

wordpress.org/plugins/webstats-matomo

Integration of statistics provided by Matomo for WordPress.

40 active installs v1.28 PHP + WP 4.0+ Updated Dec 12, 2025
statistics
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Website statistics with Matomo Safe to Use in 2026?

Generally Safe

Score 100/100

Website statistics with Matomo has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The webstats-matomo plugin v1.28 presents a mixed security profile. On the positive side, there are no identified CVEs in its history, suggesting a history of relative stability and prompt patching if issues have arisen. The static analysis also indicates a lack of dangerous functions and a commitment to prepared statements for all SQL queries, which are excellent security practices.

However, several concerning signals emerge from the static analysis. The presence of a flow with an unsanitized path in the taint analysis, even without a critical or high severity rating, warrants attention as it indicates a potential vector for path traversal or file inclusion vulnerabilities if exploited. Furthermore, a very low percentage of properly escaped output (17%) is a significant concern, as it exposes the plugin to cross-site scripting (XSS) vulnerabilities if user-supplied data is not properly sanitized before being displayed to users. The absence of nonce and capability checks on the identified entry points, though the attack surface appears minimal, also leaves room for potential unauthorized actions or information disclosure in specific scenarios.

In conclusion, while the plugin benefits from a clean vulnerability history and secure SQL handling, the high proportion of unescaped output and the identified unsanitized path flow represent notable weaknesses. These areas should be prioritized for immediate review and remediation to strengthen the plugin's overall security posture and mitigate potential risks.

Key Concerns

  • Unsanitized path flow identified
  • Low percentage of properly escaped output
  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
None known

Website statistics with Matomo Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Website statistics with Matomo Release Timeline

v1.28Current
v1.27
v1.26
v1.25
v1.24
v1.23
v1.22
v1.21
v1.20
v1.13
v1.12
v1.11
v1.10
v1.9
v1.8
v1.7
v1.6
v1.5
v1.4
v1.3
Code Analysis
Analyzed Mar 16, 2026

Website statistics with Matomo Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
29
6 escaped
Nonce Checks
0
Capability Checks
0
File Operations
6
External Requests
2
Bundled Libraries
0

Output Escaping

17% escaped35 total outputs
Data Flows · Security
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<proxy> (proxy\proxy.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Website statistics with Matomo Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionwp_footerwebstats-matomo.php:49
actionwpmu_new_blogwebstats-matomo.php:51
actionplugins_loadedwebstats-matomo.php:52
actionadmin_menuwebstats-matomo.php:53
actionadmin_initwebstats-matomo.php:54
actionwp_dashboard_setupwebstats-matomo.php:55
actionupdated_optionwebstats-matomo.php:56
Maintenance & Trust

Website statistics with Matomo Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 12, 2025
PHP min version
Downloads5K

Community Trust

Rating0/100
Number of ratings0
Active installs40
Developer Profile

Website statistics with Matomo Developer Profile

Arno Welzel

5 plugins · 29K total installs

79
trust score
Avg Security Score
100/100
Avg Patch Time
364 days
View full developer profile
Detection Fingerprints

How We Detect Website statistics with Matomo

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/webstats-matomo/proxy/matomo.php
Script Paths
/wp-content/plugins/webstats-matomo/proxy/matomo.php
Version Parameters
webstats-matomo/style.css?ver=

HTML / DOM Fingerprints

CSS Classes
wsm_text
JS Globals
idSitematomoTrackingApiUrl_paq
FAQ

Frequently Asked Questions about Website statistics with Matomo