YD WordPress.com Stats Integration Security & Risk Analysis

wordpress.org/plugins/yd-wordpresscom-stats-integration

Import your Wordpress.com statistics in your posts meta fields automatically

10 active installs v0.1.1 PHP + WP 2.8+ Updated Unknown
adminadministrationautomaticpostposts
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is YD WordPress.com Stats Integration Safe to Use in 2026?

Generally Safe

Score 100/100

YD WordPress.com Stats Integration has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The yd-wordpresscom-stats-integration plugin v0.1.1 exhibits a generally good security posture, as indicated by the absence of known vulnerabilities and a robust approach to SQL query protection and nonce/capability checks. The code signals show a high number of output operations, which is positive, but a significant concern arises from the low percentage (4%) of properly escaped outputs. This suggests a potential for cross-site scripting (XSS) vulnerabilities if user-supplied data is rendered without adequate sanitization.

The taint analysis reveals one flow with an unsanitized path, although it's not classified as critical or high severity. This is a minor concern, but it highlights a potential area where attacker-controlled input might influence file operations or other path-dependent functions in unexpected ways.

The plugin's vulnerability history is clean, with no recorded CVEs. This is a strong indicator of responsible development practices in the past. However, the low escape rate for outputs and the single unsanitized path flow, despite their current low severity, warrant attention. The plugin's strengths lie in its secure handling of SQL and its use of WordPress security features. The primary weakness is the insufficient output escaping, which could be a significant risk if not addressed.

Key Concerns

  • Low percentage of properly escaped outputs
  • Flow with unsanitized path
Vulnerabilities
None known

YD WordPress.com Stats Integration Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

YD WordPress.com Stats Integration Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
54
2 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

4% escaped56 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

2 flows1 with unsanitized paths
form_footer (inc\yd-widget-framework.inc.php:484)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

YD WordPress.com Stats Integration Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadmin_menuinc\yd-widget-framework.inc.php:41
actionwidgets_initinc\yd-widget-framework.inc.php:42
actionwp_print_stylesinc\yd-widget-framework.inc.php:44
actionplugins_loadedinc\yd-widget-framework.inc.php:45
actionwp_footerinc\yd-widget-framework.inc.php:46

Scheduled Events 2

yd_hourly_event
yd_daily_event
Maintenance & Trust

YD WordPress.com Stats Integration Maintenance & Trust

Maintenance Signals

WordPress version tested3.0.5
Last updatedUnknown
PHP min version
Downloads5K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

YD WordPress.com Stats Integration Developer Profile

Yann at WP&Co

14 plugins · 180 total installs

86
trust score
Avg Security Score
88/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect YD WordPress.com Stats Integration

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/yd-wordpresscom-stats-integration/css/yd.css

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about YD WordPress.com Stats Integration