
WP.org Plugin Stats Security & Risk Analysis
wordpress.org/plugins/wp-org-plugin-statsWordPress.org Plugin Stats will be shown by Plugin API. You can use anywhere on your website
Is WP.org Plugin Stats Safe to Use in 2026?
Generally Safe
Score 85/100WP.org Plugin Stats has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "wp-org-plugin-stats" v1.0.6 exhibits a generally strong security posture with good practices observed in several areas. The absence of known CVEs and unpatched vulnerabilities is a significant positive. Furthermore, the plugin demonstrates excellent use of prepared statements for all SQL queries and a good rate of output escaping (79%). The presence of nonce and capability checks on most entry points (6 out of 7 total, with 0 unprotected) is also commendable. However, the use of the `unserialize` function is a notable concern, as it can be a vector for remote code execution if not properly handled and if the serialized data can be influenced by an attacker. While the taint analysis did not reveal critical or high severity flows, the two flows with unsanitized paths warrant further investigation to ensure no sensitive data is exposed or manipulated.
Key Concerns
- Use of unserialize function
- Flows with unsanitized paths found
WP.org Plugin Stats Security Vulnerabilities
WP.org Plugin Stats Release Timeline
WP.org Plugin Stats Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
WP.org Plugin Stats Attack Surface
AJAX Handlers 6
Shortcodes 1
WordPress Hooks 20
Scheduled Events 1
Maintenance & Trust
WP.org Plugin Stats Maintenance & Trust
Maintenance Signals
Community Trust
WP.org Plugin Stats Alternatives
Extension Info Exporter
extension-info-exporter
Professional WordPress plugin export tool for plugin inventory management and audit reports.
I Make Plugins
i-make-plugins
For plugin authors. Showcase your plugins on your WordPress site. You only update your readme.txt files!
My Plugin Information – Fetch Data from WordPress.org
my-plugin-information
Fetch plugin data from WordPress.org using a simple shortcode. Shows version, installs, ratings, and more. Cached for speed, auto-updated hourly.
Plugin Information Card
plugin-information-card
This plugin adds the functionality to output information about plugins in the WordPress plugin directory.
WP.org Plugin Stats Developer Profile
49 plugins · 43K total installs
How We Detect WP.org Plugin Stats
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-org-plugin-stats/assets/css/plugin-survey.cssHTML / DOM Fingerprints
jltwporgst-deactivate-survey-overlayjltwporgst-deactivate-survey-modaljltwporgst-deactivate-survey-headerjltwporgst-deactivate-infojltwporgst-deactivate-content-wrapperjltwporgst-deactivate-form-wrapperjltwporgst-deactivate-input-wrapperjltwporgst-deactivate-feedback-dialog-input+2 moreid="jltwporgst-deactivate-survey-overlay"id="jltwporgst-deactivate-survey-modal"id="jltwporgst-deactivate-feedback-no_longer_needed"id="jltwporgst-deactivate-feedback-found_a_better_plugin"id="jltwporgst-deactivate-feedback-couldnt_get_the_plugin_to_work"id="jltwporgst-deactivate-feedback-temporary_deactivation"+5 moreJLTWPORGST/wp-json/jltwporgst/v1/deactivation-survey