
WP Themes & Plugins Stats Security & Risk Analysis
wordpress.org/plugins/wp-themes-plugins-statsThe WP Themes & Plugins Stats plugin automatically fetch theme and plugin stats ( name, active installs, 5-star ratings, etc.
Is WP Themes & Plugins Stats Safe to Use in 2026?
Generally Safe
Score 100/100WP Themes & Plugins Stats has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-themes-plugins-stats v1.1.3 plugin demonstrates a generally good security posture based on the provided static analysis. A significant strength is the absence of dangerous functions, raw SQL queries, and file operations, coupled with near-perfect output escaping. The limited number of total flows analyzed in taint analysis, with none exhibiting unsanitized paths, further bolsters confidence in the code's sanitization practices. The plugin also has a clean vulnerability history, with no known CVEs, suggesting a history of secure development or prompt patching.
However, there are areas for attention. The presence of 24 shortcodes represents a substantial attack surface, and while the analysis indicates no unprotected entry points, the sheer number of shortcodes could increase the likelihood of future vulnerabilities if not meticulously secured. The plugin makes 4 external HTTP requests, which can introduce risks if the target endpoints are compromised or if the plugin does not properly validate or sanitize the data being sent or received. Finally, while a nonce check is present, the complete lack of capability checks on any entry points is a significant concern. This means that any user, regardless of their role or permissions, could potentially interact with the plugin's functionalities, opening the door to unauthorized actions or information disclosure.
Key Concerns
- No capability checks on entry points
- Large attack surface (24 shortcodes)
- External HTTP requests present
WP Themes & Plugins Stats Security Vulnerabilities
WP Themes & Plugins Stats Code Analysis
Output Escaping
Data Flow Analysis
WP Themes & Plugins Stats Attack Surface
Shortcodes 24
WordPress Hooks 3
Maintenance & Trust
WP Themes & Plugins Stats Maintenance & Trust
Maintenance Signals
Community Trust
WP Themes & Plugins Stats Alternatives
WPMU Plugin Stats
wpmu-plugin-stats
Gives network admins an easy way to see what plugins are actively used on the sites of a multisite installation
WP Statistics – Simple, privacy-friendly Google Analytics alternative
wp-statistics
Get website traffic insights with GDPR/CCPA compliant, privacy-friendly analytics. Includes visitor data, stunning graphs, and no data sharing.
ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin)
google-analytics-dashboard-for-wp
Connects Google Analytics with your WordPress site. Displays stats to help you understand your users and site content on a whole new level!
Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative)
burst-statistics
Analytics you'll actually use. Privacy-friendly, zero config, and designed to be actionable. Get insights, not just raw data.
Statify
statify
Visitor statistics for WordPress with focus on data protection, transparency and clarity. Perfect as a widget in your WordPress Dashboard.
WP Themes & Plugins Stats Developer Profile
16 plugins · 14K total installs
How We Detect WP Themes & Plugins Stats
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-themes-plugins-stats/assets/css/adst-style.css/wp-content/plugins/wp-themes-plugins-stats/assets/js/adst-human-readable.js/wp-content/plugins/wp-themes-plugins-stats/assets/js/adst-human-readable.jswp-themes-plugins-stats/assets/css/adst-style.css?ver=wp-themes-plugins-stats/assets/js/adst-human-readable.js?ver=HTML / DOM Fingerprints
[adv_stats_name][adv_stats_active_install][adv_stats_version][adv_stats_ratings]