
YD WordPress.com Stats Integration Security & Risk Analysis
wordpress.org/plugins/yd-wordpresscom-stats-integrationImport your Wordpress.com statistics in your posts meta fields automatically
Is YD WordPress.com Stats Integration Safe to Use in 2026?
Generally Safe
Score 100/100YD WordPress.com Stats Integration has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The yd-wordpresscom-stats-integration plugin v0.1.1 exhibits a generally good security posture, as indicated by the absence of known vulnerabilities and a robust approach to SQL query protection and nonce/capability checks. The code signals show a high number of output operations, which is positive, but a significant concern arises from the low percentage (4%) of properly escaped outputs. This suggests a potential for cross-site scripting (XSS) vulnerabilities if user-supplied data is rendered without adequate sanitization.
The taint analysis reveals one flow with an unsanitized path, although it's not classified as critical or high severity. This is a minor concern, but it highlights a potential area where attacker-controlled input might influence file operations or other path-dependent functions in unexpected ways.
The plugin's vulnerability history is clean, with no recorded CVEs. This is a strong indicator of responsible development practices in the past. However, the low escape rate for outputs and the single unsanitized path flow, despite their current low severity, warrant attention. The plugin's strengths lie in its secure handling of SQL and its use of WordPress security features. The primary weakness is the insufficient output escaping, which could be a significant risk if not addressed.
Key Concerns
- Low percentage of properly escaped outputs
- Flow with unsanitized path
YD WordPress.com Stats Integration Security Vulnerabilities
YD WordPress.com Stats Integration Code Analysis
Output Escaping
Data Flow Analysis
YD WordPress.com Stats Integration Attack Surface
WordPress Hooks 5
Scheduled Events 2
Maintenance & Trust
YD WordPress.com Stats Integration Maintenance & Trust
Maintenance Signals
Community Trust
YD WordPress.com Stats Integration Alternatives
Custom Posts Per Page
custom-posts-per-page
Custom Posts Per Page provides a settings page in your WordPress admin that allows you to specify how many posts are displayed for different views.
Custom Posts Per Page Reloaded
custom-posts-per-page-reloaded
Custom Posts Per Page Reloaded provides a settings page in your WordPress admin that allows you to specify how many posts are displayed for different …
Schedule Post Changes With PublishPress Future: Unpublish, Delete, Change Status, Trash, Change Categories
post-expirator
PublishPress Future can make scheduled changes to your content. You can unpublish posts, move posts to a new status, update the categories, and more.
WP Admin UI Customize
wp-admin-ui-customize
Customize the management screen UI.
LH Archived Post Status
lh-archived-post-status
Allows posts and pages to be archived so you can remove content from the main loop and feed without having to trash it.
YD WordPress.com Stats Integration Developer Profile
14 plugins · 180 total installs
How We Detect YD WordPress.com Stats Integration
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/yd-wordpresscom-stats-integration/css/yd.css