
WP Show Stats Security & Risk Analysis
wordpress.org/plugins/wp-show-statsReal time and complete stats to your WP site. Comprehensive WordPress plugin for your personal dashboard and to keep track on all WordPress elements.
Is WP Show Stats Safe to Use in 2026?
Use With Caution
Score 63/100WP Show Stats has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The wp-show-stats v1.5 plugin exhibits several concerning security practices that outweigh its apparent lack of directly exploitable entry points in the static analysis. The significant presence of the `unserialize` function, combined with the absence of nonce and capability checks, creates a substantial risk. Taint analysis revealing two high-severity flows with unsanitized paths directly points to potential vulnerabilities, likely exploitable through the use of `unserialize` on untrusted input. The complete lack of prepared statements for SQL queries and the complete absence of output escaping for numerous outputs are critical oversights that leave the plugin highly susceptible to various injection attacks.
The vulnerability history indicates a pattern of Cross-Site Request Forgery (CSRF) vulnerabilities, with one medium-severity CVE remaining unpatched. While the current static analysis doesn't explicitly highlight CSRF, the historical trend, coupled with the lack of proper security measures like nonces and capability checks, suggests this could be a recurring issue or a consequence of the broader lack of sanitization and authorization. The plugin's strengths lie in its seemingly limited attack surface as reported, but this is severely undermined by the dangerous functions, lack of fundamental security checks, and evident data handling flaws. Overall, this plugin presents a high risk due to these fundamental security deficiencies.
Key Concerns
- Unpatched CVE: 1 medium severity
- High severity taint flows: 2
- Dangerous function: unserialize present
- SQL queries: 0% using prepared statements
- Output escaping: 0% properly escaped
- Nonce checks: 0
- Capability checks: 0
WP Show Stats Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WP Show Stats <= 1.5 - Cross-Site Request Forgery
WP Show Stats Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Show Stats Attack Surface
WordPress Hooks 5
Maintenance & Trust
WP Show Stats Maintenance & Trust
Maintenance Signals
Community Trust
WP Show Stats Alternatives
Yoast SEO – Advanced SEO with real-time guidance and built-in AI
wordpress-seo
Improve your SEO with real-time feedback, schema, and clear guidance. Upgrade for AI tools, Google Docs integration, and 24/7 support, no hidden fees.
ACF Content Analysis for Yoast SEO
acf-content-analysis-for-yoast-seo
WordPress plugin that adds the content of all ACF fields to the Yoast SEO score analysis.
BoldGrid Easy SEO – Simple and Effective SEO
boldgrid-easy-seo
Easy SEO helps you easily create keyword rich content and rank higher in the search engines.
Semrush SEO Writing Assistant
semrush-seo-writing-assistant
The Semrush SEO Writing Assistant provides instant recommendations for content optimization based on the best-performing articles in Google's top 10.
Post Admin Word Count
post-admin-word-count
Adds a sortable word count column to the admin post list for all public post types. Efficient, lightweight and built with modern best practices.
WP Show Stats Developer Profile
4 plugins · 3K total installs
How We Detect WP Show Stats
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-show-stats/css/wp-show-stats-admin.css/wp-content/plugins/wp-show-stats/css/jquery-ui.min.csshttps://www.google.com/jsapiField_Date.jsHTML / DOM Fingerprints
google