
Word Stats Security & Risk Analysis
wordpress.org/plugins/word-statsA suite of word counters, keyword counters and readability analysis for your blog.
Is Word Stats Safe to Use in 2026?
Generally Safe
Score 85/100Word Stats has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "word-stats" v4.5.1 plugin exhibits a generally good security posture with no recorded vulnerabilities and a strong emphasis on prepared statements for SQL queries. The static analysis reveals a minimal attack surface, with all identified entry points being protected. However, there are significant concerns regarding the use of dangerous functions like `create_function` and `unserialize`, which can be exploited if they process untrusted input. Furthermore, a low percentage of output escaping (37%) is a notable weakness, potentially leading to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not properly sanitized before being displayed. The absence of nonce checks and capability checks on the single shortcode is also a concern, as it could allow unauthorized users to trigger its functionality. While the plugin has a clean vulnerability history, the identified code signals suggest a latent risk that could be exploited in the absence of proper input validation and output sanitization.
Key Concerns
- Use of dangerous function: create_function
- Use of dangerous function: unserialize
- Low output escaping percentage
- Missing nonce check on shortcode
- Missing capability check on shortcode
Word Stats Security Vulnerabilities
Word Stats Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Word Stats Attack Surface
Shortcodes 1
WordPress Hooks 14
Scheduled Events 1
Maintenance & Trust
Word Stats Maintenance & Trust
Maintenance Signals
Community Trust
Word Stats Alternatives
Mirolabs AI SEO
mirolabs-ai-seo
Powerful AI-first SEO suite with Google Search Console integration, keyword research, content optimization, and more.
Search by GOGO GET
search-by-gogo-get
GOGO GET analyzes your site with AI, then dynamically creates an integrated Search bar without coding. Dashboard views show live Search analytics etc.
CallRail Phone Call Tracking
callrail-phone-call-tracking
Dynamically swap CallRail tracking phone numbers based on the visitor's referring source.
Simple SEO
cds-simple-seo
Allows the modification of META titles, descriptions and keywords for all pages and posts. Also allows for default setting for of META title, descript …
Surfer – WordPress Plugin
surferseo
Connect Surfer's Content Editor to WordPress. Write and optimize your articles for SEO, find new keyword ideas and publish straight to WordPress.
Word Stats Developer Profile
2 plugins · 210 total installs
How We Detect Word Stats
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/word-stats/css/style.css/wp-content/plugins/word-stats/js/word-stats.js/wp-content/plugins/word-stats/js/word-stats.jsword-stats/css/style.css?ver=word-stats/js/word-stats.js?ver=HTML / DOM Fingerprints
word-stats-counts<ul class="word-stats-counts">