WP-SEOstats Security & Risk Analysis

wordpress.org/plugins/wp-seostats

Add SEO stats to the Admin Toolbar in every page/post and also in the edit page/post.

10 active installs v2.4 PHP + WP 3.6.0+ Updated Dec 24, 2014
search-engine-statsseoseo-statsstatitcstoolbar
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP-SEOstats Safe to Use in 2026?

Generally Safe

Score 85/100

WP-SEOstats has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The wp-seostats v2.4 plugin exhibits a generally good security posture with no recorded vulnerabilities and a limited attack surface. The code analysis indicates that while there are a moderate number of SQL queries and output operations, a significant portion of these are handled securely through prepared statements and proper escaping. The plugin's lack of reported CVEs over its history is a positive indicator of its stability and the developers' attention to security.

However, there are some areas for improvement. The absence of any nonce or capability checks for its entry points, despite having zero unprotected ones currently, presents a potential future risk if new, unprotected entry points are introduced. The presence of a taint flow with unsanitized paths, even without critical or high severity, suggests a potential for path traversal or other file system-related vulnerabilities if the input is not meticulously validated at all stages. Additionally, the plugin performs file operations and external HTTP requests, which, while not inherently risky, require diligent validation of all external inputs to prevent exploitation.

Overall, wp-seostats v2.4 appears to be a relatively safe plugin, especially given its clean vulnerability history. The primary concerns stem from the lack of explicit security checks on potential entry points and the identified unsanitized path flow, which, if exploited, could lead to security issues. Continued vigilance in input validation and considering the implementation of capability checks would further strengthen its security.

Key Concerns

  • Taint flow with unsanitized paths
  • No nonce checks
  • No capability checks
  • Output escaping is not fully implemented (58%)
  • SQL queries not fully using prepared statements (71%)
Vulnerabilities
None known

WP-SEOstats Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

WP-SEOstats Code Analysis

Dangerous Functions
0
Raw SQL Queries
4
10 prepared
Unescaped Output
22
30 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
6
Bundled Libraries
0

SQL Query Safety

71% prepared14 total queries

Output Escaping

58% escaped52 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<Majestic-SEO> (Majestic-SEO.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

WP-SEOstats Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_menuWP-SEOstats.php:25
actioninitWP-SEOstats.php:88
actionadmin_bar_menuWP-SEOstats.php:166
actionwp_dashboard_setupWP-SEOstats.php:173
Maintenance & Trust

WP-SEOstats Maintenance & Trust

Maintenance Signals

WordPress version tested3.6.0
Last updatedDec 24, 2014
PHP min version
Downloads9K

Community Trust

Rating90/100
Number of ratings2
Active installs10
Developer Profile

WP-SEOstats Developer Profile

DrMosko

4 plugins · 50 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP-SEOstats

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-seostats/Alexa-Graph.php/wp-content/plugins/wp-seostats/SemRush-Graph.php/wp-content/plugins/wp-seostats/Majestic-SEO.php/wp-content/plugins/wp-seostats/Alexa-xml.php

HTML / DOM Fingerprints

CSS Classes
WP_SEOstatsgooglePRWP_SEOstatsgoogleTBWP_SEOstatsgpsWP_SEOstatstwitterWP_SEOstatsfacebookWP_SEOstatsalexaWP_SEOstatsopensiteexWPShabbat-Donation
FAQ

Frequently Asked Questions about WP-SEOstats