
WP Network Stats Security & Risk Analysis
wordpress.org/plugins/wp-network-statsView/Export network statistics related to users & plugins per site, themes, plugins and other site stats in your multisite network.
Is WP Network Stats Safe to Use in 2026?
Generally Safe
Score 85/100WP Network Stats has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-network-stats" plugin v1.0.4 exhibits a generally positive security posture, with no known CVEs and a low number of code signals that indicate immediate high risk. The absence of critical or high severity taint flows, dangerous functions, and external HTTP requests are strong indicators of good development practices. The plugin also appears to have a minimal attack surface, with all entry points lacking authentication checks, which is a significant advantage.
However, there are areas for concern. The low percentage of properly escaped output (21%) suggests a risk of Cross-Site Scripting (XSS) vulnerabilities, especially if user-supplied data is involved in these unescaped outputs. While the SQL query preparation rate is decent at 73%, the remaining 27% could still be a vector for SQL injection if those queries handle user input. The complete lack of nonce checks across all entry points is also a notable weakness, potentially opening doors to Cross-Site Request Forgery (CSRF) attacks.
The plugin's vulnerability history being clean is a positive sign, but it could also be attributed to its limited scope or fewer past analyses. Overall, "wp-network-stats" v1.0.4 has strengths in its limited attack surface and lack of known severe vulnerabilities. However, the handling of output and the absence of nonce checks are significant weaknesses that require attention to mitigate potential risks.
Key Concerns
- Low output escaping rate (21%)
- Some SQL queries not using prepared statements
- Zero nonce checks on entry points
WP Network Stats Security Vulnerabilities
WP Network Stats Release Timeline
WP Network Stats Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Network Stats Attack Surface
WordPress Hooks 12
Scheduled Events 7
Maintenance & Trust
WP Network Stats Maintenance & Trust
Maintenance Signals
Community Trust
WP Network Stats Alternatives
Multisite Theme Statistics
wordpress-mu-theme-stats
Adds theme usage statistics within your network, shows themes by user and most popular themes.
Network Plugin Auditor
network-plugin-auditor
For multisite/network installations only. Adds columns to your network admin to show which sites are using each plugin and theme.
Hyper Admins
hyper-admins
Simplify administration tasks for super-admins.
Mission Control
mission-control
Effortlessly take control of all the sites on your network. Assign levels to your sites and manage the features available to each level.
Multisite Administration Tools
multisite-administration-tools
Adds information to the network admin sites, plugins and themes page. Allows you to easily see what theme and plugins are enabled on a site.
WP Network Stats Developer Profile
2 plugins · 20 total installs
How We Detect WP Network Stats
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-network-stats/admin/js/network-stats-admin.js/wp-content/plugins/wp-network-stats/admin/js/network-stats-admin.jsHTML / DOM Fingerprints
network_stats_admin_params