
WP Page Load Stats Security & Risk Analysis
wordpress.org/plugins/wp-page-load-statsDisplay memory, page load time, average load time and query count in the footer of your site.
Is WP Page Load Stats Safe to Use in 2026?
Generally Safe
Score 100/100WP Page Load Stats has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-page-load-stats" v1.0.2 plugin exhibits a strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the plugin's attack surface. Furthermore, the code signals indicate a lack of dangerous functions, file operations, and external HTTP requests. The fact that all SQL queries utilize prepared statements is a commendable security practice.
However, a significant concern arises from the 100% unescaped output. This means that any data processed by the plugin and then displayed to users could potentially be vulnerable to Cross-Site Scripting (XSS) attacks. The absence of nonce checks and capability checks, while not directly exploitable given the limited attack surface, represents a missed opportunity to reinforce security controls should new entry points be introduced in future versions.
The vulnerability history is clean, with no recorded CVEs. This, combined with the lack of critical or high severity taint flows, suggests that the plugin has historically been developed with security in mind. Despite the excellent track record and limited attack surface, the unescaped output remains the primary, albeit potentially severe, weakness that requires attention.
Key Concerns
- Unescaped output
WP Page Load Stats Security Vulnerabilities
WP Page Load Stats Code Analysis
Output Escaping
WP Page Load Stats Attack Surface
WordPress Hooks 7
Maintenance & Trust
WP Page Load Stats Maintenance & Trust
Maintenance Signals
Community Trust
WP Page Load Stats Alternatives
Debug This
debug-this
Peek under the hood with sixty debugging reports just one click away.
Query Monitor – The developer tools panel for WordPress
query-monitor
Query Monitor is the developer tools panel for WordPress and WooCommerce.
Debug Log Manager – Conveniently Monitor and Inspect Errors
debug-log-manager
Log PHP, database and JavaScript errors via WP_DEBUG with one click. Conveniently create, view, filter and clear the debug.log file.
Page Visits Counter – Lite
page-visits-counter-lite
Display number of visits for each page in admin dashboard and browser developer-tool/console. Doesn't count page refresh as a new visit...
Debug Log – Manager Tool
debug-log-config-tool
The "Debug Log Config Tool" simplifies debugging. Toggle logging,queries , view levels, clear logs from dashboard.
WP Page Load Stats Developer Profile
4 plugins · 11K total installs
How We Detect WP Page Load Stats
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-page-load-stats/style.csswp-page-load-stats/style.css?ver=HTML / DOM Fingerprints
actionsonclickdata-reset_wp_pls_statswp_pls_hide