
WP-SEOstats Security & Risk Analysis
wordpress.org/plugins/wp-seostatsAdd SEO stats to the Admin Toolbar in every page/post and also in the edit page/post.
Is WP-SEOstats Safe to Use in 2026?
Generally Safe
Score 85/100WP-SEOstats has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-seostats v2.4 plugin exhibits a generally good security posture with no recorded vulnerabilities and a limited attack surface. The code analysis indicates that while there are a moderate number of SQL queries and output operations, a significant portion of these are handled securely through prepared statements and proper escaping. The plugin's lack of reported CVEs over its history is a positive indicator of its stability and the developers' attention to security.
However, there are some areas for improvement. The absence of any nonce or capability checks for its entry points, despite having zero unprotected ones currently, presents a potential future risk if new, unprotected entry points are introduced. The presence of a taint flow with unsanitized paths, even without critical or high severity, suggests a potential for path traversal or other file system-related vulnerabilities if the input is not meticulously validated at all stages. Additionally, the plugin performs file operations and external HTTP requests, which, while not inherently risky, require diligent validation of all external inputs to prevent exploitation.
Overall, wp-seostats v2.4 appears to be a relatively safe plugin, especially given its clean vulnerability history. The primary concerns stem from the lack of explicit security checks on potential entry points and the identified unsanitized path flow, which, if exploited, could lead to security issues. Continued vigilance in input validation and considering the implementation of capability checks would further strengthen its security.
Key Concerns
- Taint flow with unsanitized paths
- No nonce checks
- No capability checks
- Output escaping is not fully implemented (58%)
- SQL queries not fully using prepared statements (71%)
WP-SEOstats Security Vulnerabilities
WP-SEOstats Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WP-SEOstats Attack Surface
WordPress Hooks 4
Maintenance & Trust
WP-SEOstats Maintenance & Trust
Maintenance Signals
Community Trust
WP-SEOstats Alternatives
Post-Analytics
post-analytics
Add Google Analytics Statistics on Admin Edit Screen for Posts and Pages.
Search Engines Blocked in Header
search-engines-blocked-in-header
Display the 'Search Engines Discouraged' notification in the WordPress Toolbar if the blog_public option has been checked.
SEO Stats Widget
seo-stats-widget
Display SEO Statistics of blog
WP Keywords Report
wp-keywords-report
Know your blog position in Google SERP
Yoast SEO – Advanced SEO with real-time guidance and built-in AI
wordpress-seo
Improve your SEO with real-time feedback, schema, and clear guidance. Upgrade for AI tools, Google Docs integration, and 24/7 support, no hidden fees.
WP-SEOstats Developer Profile
4 plugins · 50 total installs
How We Detect WP-SEOstats
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-seostats/Alexa-Graph.php/wp-content/plugins/wp-seostats/SemRush-Graph.php/wp-content/plugins/wp-seostats/Majestic-SEO.php/wp-content/plugins/wp-seostats/Alexa-xml.phpHTML / DOM Fingerprints
WP_SEOstatsgooglePRWP_SEOstatsgoogleTBWP_SEOstatsgpsWP_SEOstatstwitterWP_SEOstatsfacebookWP_SEOstatsalexaWP_SEOstatsopensiteexWPShabbat-Donation