
WP Statistics and Analytics Security & Risk Analysis
wordpress.org/plugins/wp-statistics-and-analyticsWP Statistics and Analytics is a simple plugin which, once enabled, will keep you update with page, post and user statistics with continuous updates t …
Is WP Statistics and Analytics Safe to Use in 2026?
Generally Safe
Score 85/100WP Statistics and Analytics has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "wp-statistics-and-analytics" v0.0.3 exhibits a generally strong security posture based on the provided static analysis. It demonstrates good practices by avoiding dangerous functions, performing all SQL queries using prepared statements, and incorporating nonce and capability checks on its entry points. The absence of file operations and external HTTP requests further limits its attack surface in those areas. Furthermore, the plugin has no recorded vulnerability history, indicating a lack of publicly known security flaws and suggesting a potentially well-maintained codebase.
However, a significant concern arises from the low percentage of properly escaped output. With only 10% of 51 outputs being properly escaped, there is a high probability of cross-site scripting (XSS) vulnerabilities. Although taint analysis showed no specific unsanitized paths, the general lack of output escaping is a substantial risk that could be exploited if malicious data reaches these output points. The limited number of entry points (2) and the absence of unprotected ones are positive, but the output escaping issue overshadows this otherwise positive assessment.
In conclusion, while the plugin has strengths in its handling of SQL, its use of nonces and capabilities, and its clean vulnerability history, the severe lack of output escaping represents a critical weakness. This makes it susceptible to XSS attacks, which can have significant security implications. Developers should prioritize addressing the output escaping issues to improve the overall security of the plugin.
Key Concerns
- Low percentage of properly escaped output
WP Statistics and Analytics Security Vulnerabilities
WP Statistics and Analytics Code Analysis
Output Escaping
WP Statistics and Analytics Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 6
Maintenance & Trust
WP Statistics and Analytics Maintenance & Trust
Maintenance Signals
Community Trust
WP Statistics and Analytics Alternatives
Empty WP Blog/Website
empty-wp-blog-or-website
One click solution for make your blog/website empty. Delete all your posts, pages, media(images,videos,etc) , tags and categories.
End Page Slide Box
end-page-slide-box
End Page Slide Box is to have an element in the page last paragraph that triggers End Page Slide Box to appear.
Custom Post Type Privacy
custom-post-type-privacy
Stable Tag 0.3 Custom Post Type Privacy allows WordPress authors to grant access to users and groups of users across all posts, pages and custom post …
GhostWriter
ghostwriter
Ghostwriter overrides WordPress’s author pages and feeds to emulate the full functionality provided to WordPress users.
GitHub Badge
github-badge
This plug-in allows you to create and place a GitHub css3 badge to your webpage on wordpress. With the help of this plug-in you create a css3 badge fo …
WP Statistics and Analytics Developer Profile
17 plugins · 130 total installs
How We Detect WP Statistics and Analytics
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-statistics-and-analytics/js/klick-sa-dashboard.js/wp-content/plugins/wp-statistics-and-analytics/js/klick-sa-main.js/wp-content/plugins/wp-statistics-and-analytics/js/klick-sa-frontend.jswp-statistics-and-analytics/js/klick-sa-dashboard.js?ver=wp-statistics-and-analytics/js/klick-sa-main.js?ver=wp-statistics-and-analytics/js/klick-sa-frontend.js?ver=HTML / DOM Fingerprints
klick-sa-data-containerklick-sa-overlayloading-imageklick-sa-postklick-sa-dataklick-sa-inner-dataklick-sa-pageThis plugin developed by klick-on-it.comCopyright 2017 klick on it (http://klick-on-it.com)This program is free software; you can redistribute it and/or modifyThis program is distributed in the hope that it will be useful,+2 moredata-ajax-urldata-noncedata-subactionklick_sa_ajax_obj<div class="klick-sa-data-container"><div class="klick-sa-overlay"><img class="loading-image" src="" alt="Loading.." />