
WP Uploads Stats Security & Risk Analysis
wordpress.org/plugins/wp-uploads-statsProvides you with detailed statistics about your WordPress media uploads and attachments.
Is WP Uploads Stats Safe to Use in 2026?
Generally Safe
Score 85/100WP Uploads Stats has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-uploads-stats v1.0.3 plugin exhibits a concerning security posture due to significant vulnerabilities in its code analysis. The presence of one unprotected AJAX handler represents a major entry point for potential attacks without any authentication or authorization mechanisms. Furthermore, the complete absence of nonce checks on this AJAX handler exacerbates the risk, allowing for cross-site request forgery (CSRF) attacks. The code analysis also reveals a substantial lack of security best practices, particularly with 100% of SQL queries not utilizing prepared statements, which can lead to SQL injection vulnerabilities. A mere 9% of outputs being properly escaped is also a significant weakness, increasing the risk of cross-site scripting (XSS) attacks.
While the plugin has no recorded vulnerability history (CVEs), this is not indicative of a secure plugin, especially given the current code quality. The lack of history might simply mean it hasn't been extensively audited or exploited yet. The absence of taint analysis results and dangerous functions might be due to the scope of the static analysis rather than genuine security. The plugin's strengths are minimal, perhaps its small attack surface and lack of file operations or external HTTP requests offer some limited protection. However, the critical findings in the code analysis, particularly the unprotected AJAX handler and widespread unescaped outputs and raw SQL, far outweigh these minor strengths, rendering the plugin highly risky for deployment.
Key Concerns
- Unprotected AJAX handler detected
- Missing nonce checks on AJAX handlers
- SQL queries not using prepared statements
- Low percentage of properly escaped output
- No capability checks on entry points
WP Uploads Stats Security Vulnerabilities
WP Uploads Stats Code Analysis
SQL Query Safety
Output Escaping
WP Uploads Stats Attack Surface
AJAX Handlers 1
WordPress Hooks 10
Maintenance & Trust
WP Uploads Stats Maintenance & Trust
Maintenance Signals
Community Trust
WP Uploads Stats Alternatives
WP-Stats
wp-stats
Display your WordPress blog statistics. Ranging from general total statistics, some of my plugins statistics and top 10 statistics.
File Upload For WPForms – Filenzo
file-upload-for-wpforms
Enhance WPForms with a secure file upload field, allowing users to upload files directly through forms.
ExtraWatch PRO (Live Stats, Heatmap, Click tracking, Download Monitor and more)
extrawatch-pro
Optimize website and increase sales. Watch your visitors in real time, Click Heatmap, Conversion Tracking, Download monitor, Anti-spam, Email Reports
Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative)
burst-statistics
Analytics you'll actually use. Privacy-friendly, zero config, and designed to be actionable. Get insights, not just raw data.
Statify
statify
Visitor statistics for WordPress with focus on data protection, transparency and clarity. Perfect as a widget in your WordPress Dashboard.
WP Uploads Stats Developer Profile
7 plugins · 4K total installs
How We Detect WP Uploads Stats
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-uploads-stats/css//wp-content/plugins/wp-uploads-stats/js//wp-content/plugins/wp-uploads-stats/js/wp-uploads-stats.jswp-uploads-stats/css/wp-uploads-stats.css?ver=wp-uploads-stats/js/wp-uploads-stats.js?ver=HTML / DOM Fingerprints
WP_Uploads_Stats