
WP Post Statistics (Visitors & Visits Counter) Security & Risk Analysis
wordpress.org/plugins/wp-post-real-time-statisticsa simple tool to know your post statistics
Is WP Post Statistics (Visitors & Visits Counter) Safe to Use in 2026?
Generally Safe
Score 91/100WP Post Statistics (Visitors & Visits Counter) has a strong security track record. Known vulnerabilities have been patched promptly.
The "wp-post-real-time-statistics" plugin v2.9 exhibits a concerning security posture primarily due to its exposed attack surface and lack of robust security checks. All identified entry points, which consist of three AJAX handlers, lack any form of authentication or capability checks. This means any user, regardless of their role or permissions, can potentially interact with these handlers, opening the door to unauthorized actions or information disclosure. The presence of a taint flow with an unsanitized path is a significant red flag, suggesting a potential for local file inclusion or path traversal vulnerabilities, although its critical and high severity ratings were zero, indicating it might not be exploitable in practice without further context.
The plugin's vulnerability history, with one known high-severity Cross-site Scripting (XSS) vulnerability from May 2022, highlights past security weaknesses. While this specific vulnerability is currently patched, the pattern of past security issues, coupled with the present lack of nonce checks and capability checks on critical entry points, suggests a recurring need for more stringent security practices within the plugin's development. The moderate percentage of prepared statements for SQL queries and the generally good output escaping are positive aspects, but they are overshadowed by the significant gaps in authorization and input validation on its AJAX endpoints. The plugin's overall security is weakened by these fundamental oversights, despite some good practices in other areas.
Key Concerns
- AJAX handlers without auth checks
- Taint flow with unsanitized path
- No nonce checks
- No capability checks
- Known high severity vulnerability history
- SQL queries not fully using prepared statements
WP Post Statistics (Visitors & Visits Counter) Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WP Post Statistics (Visitors & Visits Counter) <= 2.5 - Cross-Site Scripting
WP Post Statistics (Visitors & Visits Counter) Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Post Statistics (Visitors & Visits Counter) Attack Surface
AJAX Handlers 3
WordPress Hooks 6
Maintenance & Trust
WP Post Statistics (Visitors & Visits Counter) Maintenance & Trust
Maintenance Signals
Community Trust
WP Post Statistics (Visitors & Visits Counter) Alternatives
Visitor Traffic Real Time Statistics
visitors-traffic-real-time-statistics
This plugin will help you to track your visitors, browsers, operating systems, visits and much more in one dashboard page.
WPS Visitor Counter
wps-visitor-counter
Display website visitor statistics with widget, shortcode, and Gutenberg block support.
Mechanic Visitor Counter
mechanic-visitor-counter
Mechanic Visitor Counter is a widgets which will display the Visitor counter and traffic statistics on WordPress. Some of the features offered include …
XT Visitor Counter
xt-visitor-counter
XT Visitor Counter is a widgets which will display the Visitor counter and traffic statistics on WordPress. Some of the features offered include Today …
Total Views
total-views
Count total page views on your WordPress site and display them with a simple shortcode. Customizable label, styles, and editable page views.
WP Post Statistics (Visitors & Visits Counter) Developer Profile
2 plugins · 22K total installs
How We Detect WP Post Statistics (Visitors & Visits Counter)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-post-real-time-statistics/css/jquery.jqplot.min.css/wp-content/plugins/wp-post-real-time-statistics/css/jquery-ui.css/wp-content/plugins/wp-post-real-time-statistics/css/style.css/wp-content/plugins/wp-post-real-time-statistics/js/jquery.jqplot.min.js/wp-content/plugins/wp-post-real-time-statistics/js/jqplot.cursor.min.js/wp-content/plugins/wp-post-real-time-statistics/js/jqplot.pointLabels.min.js/wp-content/plugins/wp-post-real-time-statistics/js/jqplot.barRenderer.js/wp-content/plugins/wp-post-real-time-statistics/js/jqplot.canvasAxisTickRenderer.js+5 morewp-post-real-time-statistics/css/jquery.jqplot.min.css?ver=wp-post-real-time-statistics/css/jquery-ui.css?ver=wp-post-real-time-statistics/css/style.css?ver=wp-post-real-time-statistics/js/jquery.jqplot.min.js?ver=wp-post-real-time-statistics/js/jqplot.cursor.min.js?ver=wp-post-real-time-statistics/js/jqplot.pointLabels.min.js?ver=wp-post-real-time-statistics/js/jqplot.barRenderer.js?ver=wp-post-real-time-statistics/js/jqplot.canvasAxisTickRenderer.js?ver=wp-post-real-time-statistics/js/jqplot.canvasTextRenderer.js?ver=wp-post-real-time-statistics/js/jqplot.pieRenderer.js?ver=wp-post-real-time-statistics/js/jqplot.dateAxisRenderer.js?ver=wp-post-real-time-statistics/js/jqplot.categoryAxisRenderer.js?ver=wp-post-real-time-statistics/js/main.js?ver=HTML / DOM Fingerprints
POSTSTATS_PLUGIN_URLPOSTSTATS_ADMIN_AJAXPOSTSTATS_PLUGIN_URLPOSTSTATS_ADMIN_AJAX/wp-json/poststats_first_chart/wp-json/poststats_countries_table/wp-json/poststats_cities_table