
Word Stats Security & Risk Analysis
wordpress.org/plugins/word-statsA suite of word counters, keyword counters and readability analysis for your blog.
Is Word Stats Safe to Use in 2026?
Generally Safe
Score 85/100Word Stats has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "word-stats" v4.5.1 plugin exhibits a generally good security posture with no recorded vulnerabilities and a strong emphasis on prepared statements for SQL queries. The static analysis reveals a minimal attack surface, with all identified entry points being protected. However, there are significant concerns regarding the use of dangerous functions like `create_function` and `unserialize`, which can be exploited if they process untrusted input. Furthermore, a low percentage of output escaping (37%) is a notable weakness, potentially leading to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not properly sanitized before being displayed. The absence of nonce checks and capability checks on the single shortcode is also a concern, as it could allow unauthorized users to trigger its functionality. While the plugin has a clean vulnerability history, the identified code signals suggest a latent risk that could be exploited in the absence of proper input validation and output sanitization.
Key Concerns
- Use of dangerous function: create_function
- Use of dangerous function: unserialize
- Low output escaping percentage
- Missing nonce check on shortcode
- Missing capability check on shortcode
Word Stats Security Vulnerabilities
Word Stats Release Timeline
Word Stats Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Word Stats Attack Surface
Shortcodes 1
WordPress Hooks 14
Scheduled Events 1
Maintenance & Trust
Word Stats Maintenance & Trust
Maintenance Signals
Community Trust
Word Stats Alternatives
Mirolabs AI SEO
mirolabs-ai-seo
Powerful AI-first SEO suite with Google Search Console integration, keyword research, content optimization, and more.
Search by GOGO GET
search-by-gogo-get
GOGO GET analyzes your site with AI, then dynamically creates an integrated Search bar without coding. Dashboard views show live Search analytics etc.
Seotune Search Insights
seotune-search-insights
Search Console analytics and SEO insights in your WordPress admin. Connect with OAuth; data stored in your DB. Not affiliated with Google.
CallRail Phone Call Tracking
callrail-phone-call-tracking
Dynamically swap CallRail tracking phone numbers based on the visitor's referring source.
Simple SEO
cds-simple-seo
Allows the modification of META titles, descriptions and keywords for all pages and posts. Also allows for default setting for of META title, descript …
Word Stats Developer Profile
2 plugins · 210 total installs
How We Detect Word Stats
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/word-stats/css/style.css/wp-content/plugins/word-stats/js/word-stats.js/wp-content/plugins/word-stats/js/word-stats.jsword-stats/css/style.css?ver=word-stats/js/word-stats.js?ver=HTML / DOM Fingerprints
word-stats-counts<ul class="word-stats-counts">