
WP Year End Stats Security & Risk Analysis
wordpress.org/plugins/wp-yearendstatsDisplays fancy stats about your blog which you can include in your year end review posts.
Is WP Year End Stats Safe to Use in 2026?
Generally Safe
Score 100/100WP Year End Stats has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-yearendstats v1.0 plugin presents a generally strong security posture, with no reported vulnerabilities or critical code signals like dangerous functions, file operations, or external requests. The absence of taint analysis findings and known CVEs further reinforces this positive outlook. However, there are areas for improvement. The low percentage of properly escaped output (43%) is a significant concern, as it could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is not adequately sanitized before being displayed. Additionally, the complete lack of nonce checks and capability checks, while mitigated by the current limited attack surface, creates a potential weakness if the plugin's entry points were to expand or be misused in the future. The high percentage of prepared statements for SQL queries is a positive indicator against SQL injection.
Key Concerns
- Low percentage of properly escaped output
- No nonce checks
- No capability checks
WP Year End Stats Security Vulnerabilities
WP Year End Stats Code Analysis
SQL Query Safety
Output Escaping
WP Year End Stats Attack Surface
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
WP Year End Stats Maintenance & Trust
Maintenance Signals
Community Trust
WP Year End Stats Alternatives
Site Stats Dashboard
site-stats-dashboard
Simple dashboard that displays site statistics (post count, comment count, visit count) in the admin panel.
No Page Comment
no-page-comment
An admin interface to control the default comment and trackback settings on new posts, pages and custom post types.
No External Links
mihdan-no-external-links
Convert external links into internal links, site wide or post/page specific. Add NoFollow, Click logging, and more...
news ticker benaceur
news-ticker-benaceur
This plugin allow you to display the latest posts or latest comments in a bar with twenty seven beautiful animations and effects...
Disable Feeds and Comments
disable-rss-feeds-and-comments
This WordPress plugin, "Disable RSS Feeds and Comments," gives you the ability to turn off both the RSS feeds and comments on pages and/or p …
WP Year End Stats Developer Profile
16 plugins · 21K total installs
How We Detect WP Year End Stats
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-yearendstats/assets/js/vendor/flot/jquery.flot.min.js/wp-content/plugins/wp-yearendstats/assets/js/vendor/flot/jquery.flot.js/wp-content/plugins/wp-yearendstats/assets/js/vendor/flot/jquery.flot.pie.min.js/wp-content/plugins/wp-yearendstats/assets/js/vendor/flot/jquery.flot.pie.js/wp-content/plugins/wp-yearendstats/assets/js/vendor/flot/jquery.flot.resize.min.js/wp-content/plugins/wp-yearendstats/assets/js/vendor/flot/jquery.flot.resize.js/wp-content/plugins/wp-yearendstats/assets/js/vendor/flot/jquery.flot.stack.min.js/wp-content/plugins/wp-yearendstats/assets/js/vendor/flot/jquery.flot.stack.js+2 moreassets/js/vendor/flot/jquery.flot.min.jsassets/js/vendor/flot/jquery.flot.jsassets/js/vendor/flot/jquery.flot.pie.min.jsassets/js/vendor/flot/jquery.flot.pie.jsassets/js/vendor/flot/jquery.flot.resize.min.jsassets/js/vendor/flot/jquery.flot.resize.js+4 morewp-yearendstats/style.css?ver=wp-yearendstats/script.js?ver=wp-yearendstats/admin-script.js?ver=HTML / DOM Fingerprints
wrapform-tableid="year_1"name="year_1"id="range"name="range"id="year_2"name="year_2"+5 more<div id = "posts_chart"><div id = "comments_chart"><div id="avg_post_length_chart"><div id = "total_post_length_chart">