
WP Network Stats Security & Risk Analysis
wordpress.org/plugins/wp-network-statsView/Export network statistics related to users & plugins per site, themes, plugins and other site stats in your multisite network.
Is WP Network Stats Safe to Use in 2026?
Generally Safe
Score 85/100WP Network Stats has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-network-stats" plugin v1.0.4 exhibits a generally positive security posture, with no known CVEs and a low number of code signals that indicate immediate high risk. The absence of critical or high severity taint flows, dangerous functions, and external HTTP requests are strong indicators of good development practices. The plugin also appears to have a minimal attack surface, with all entry points lacking authentication checks, which is a significant advantage.
However, there are areas for concern. The low percentage of properly escaped output (21%) suggests a risk of Cross-Site Scripting (XSS) vulnerabilities, especially if user-supplied data is involved in these unescaped outputs. While the SQL query preparation rate is decent at 73%, the remaining 27% could still be a vector for SQL injection if those queries handle user input. The complete lack of nonce checks across all entry points is also a notable weakness, potentially opening doors to Cross-Site Request Forgery (CSRF) attacks.
The plugin's vulnerability history being clean is a positive sign, but it could also be attributed to its limited scope or fewer past analyses. Overall, "wp-network-stats" v1.0.4 has strengths in its limited attack surface and lack of known severe vulnerabilities. However, the handling of output and the absence of nonce checks are significant weaknesses that require attention to mitigate potential risks.
Key Concerns
- Low output escaping rate (21%)
- Some SQL queries not using prepared statements
- Zero nonce checks on entry points
WP Network Stats Security Vulnerabilities
WP Network Stats Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Network Stats Attack Surface
WordPress Hooks 12
Scheduled Events 7
Maintenance & Trust
WP Network Stats Maintenance & Trust
Maintenance Signals
Community Trust
WP Network Stats Alternatives
Multisite Administration Tools
multisite-administration-tools
Adds information to the network admin sites, plugins and themes page. Allows you to easily see what theme and plugins are enabled on a site.
Simple Custom CSS and JS
custom-css-js
Easily add Custom CSS or JS to your website with an awesome editor.
WP Statistics – Simple, privacy-friendly Google Analytics alternative
wp-statistics
Get website traffic insights with GDPR/CCPA compliant, privacy-friendly analytics. Includes visitor data, stunning graphs, and no data sharing.
ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin)
google-analytics-dashboard-for-wp
Connects Google Analytics with your WordPress site. Displays stats to help you understand your users and site content on a whole new level!
SiteOrigin CSS
so-css
Powerful, simple CSS editing for WordPress. Visual controls & real-time previews for effortless site customization.
WP Network Stats Developer Profile
2 plugins · 20 total installs
How We Detect WP Network Stats
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-network-stats/admin/js/network-stats-admin.js/wp-content/plugins/wp-network-stats/admin/js/network-stats-admin.jsHTML / DOM Fingerprints
network_stats_admin_params