SlimStat Analytics
by VeronaLabs · Analytics
Also makes 3 other plugins · 677K+ installs across the portfolio →
Real-time WordPress analytics that stay on your own server: pageviews, outbound links, WooCommerce funnels, all privacy-first and GDPR-ready.
91 health vs 64 average across 1,028 Analytics plugins
Directory ranking optimization
How it's scored →How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.
Excellent listing optimization
Biggest win: Support resolution
To rank higher: Mark more forum threads resolved — the resolved ratio feeds the ranking.
Get the full rank-higher report →Daily downloads
Since 2022-10-05 · 1,421 days · wp.org + Plugin Pulse archive
30-day downloads
Rolling 30-day volume · peaks are release surges
8.7K
now · peak 214.2K
Directory rank vs rivals
wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you
Rating trend
Star average over time · dips mark rough releases
Update activity
How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.
Release cadence
Actively maintainedHow often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.
17
releases in the last 12 months
2mo ago
latest release · v5.5.0
211
tagged releases on record
Recent releases
What its installed base runs
via wordpress.orgShare of active installs on each version of this plugin · 32% run the current release. Green is the current release; a big slice on older versions is a user base that has stopped updating.
Estimated active installs
The public count shows “70K+”. Our estimate pins where the real number sits.
Refined from the date this plugin crossed into its current band.
Install history · since 2015-03-10 · 1,496 observations
Estimated value
What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.
Est. annual revenue
Est. acquisition value
No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price. A declining trend compresses what a buyer would pay.
Details
Recent reviews
All reviews on wp.org ↗- ★★★★★ sperorisk5mo ago
A recent update didn’t go well for me, but Parham and the support team worked diligently (and seemingly tirelessly) to investigate and solve the problem. (If you’ve seen a few recent updates, I’ll take credit for those.) I’ve used SlimStat for many, many years, and don’t know a better way of getting a sense of who is visiting the site. This was the first time that I had an issue, and I’m amazed at how much time and energy they devoted to my problem (for my meager $39/year). Everyone thinks there’s just WordPress, but there are thousands of different plugins and just as many server settings and, therefore, millions of different configurations that could cause problems. If you have a problem, these guys will work with you to solve it. It’s the best stats plugin that I used, and the best support team that I’ve needed. (Thanks guys!)
Read on wp.org ↗ - ★★★★★ strandpuller5mo ago
I had trouble getting the browser cap to stay on. I contacted SlimStat support, and they were exceptionally helpful in solving the problem. They worked with me repeatedly until the browser cap problem was fixed. I am impressed with the quality of support they provided.
Read on wp.org ↗ - ★★★★★ Ryan6mo ago
the lastest update Version 5.4.1 is the worst I have ever used. This topic was modified 4 months, 1 week ago by Ryan.
Read on wp.org ↗ - ★★★★★ alamea11mo ago
fantastic plugin, fast and good filter options
Read on wp.org ↗ - ★★★★★ Marcia1.3y ago
Last update to version 5.4 made the site slow and causing 503 errors. This is terrible. Every time you change something, you break everything. I uninstalled it and will get a better competitor. This topic was modified 1 year, 2 months ago by Marcia. This topic was modified 4 months, 1 week ago by Marcia.
Read on wp.org ↗ - ★★★★★ lweb1.3y ago
Everything became chargeable overnight. So I uninstalled this plugin from my 72 sites. Goodbye, Slimstat
Read on wp.org ↗ - ★★★★★ Senri Miura2.2y ago
I installed this as an alternative to NewStatPress, which is no longer being maintained.Thank you for providing such a great plugin.SlimStat Analytics is an excellent plugin that is easy to use and has many functions, but I would like it to be even better if the widget could display page views (yesterday, today), etc.
Read on wp.org ↗ - ★★★★★ craig.keefner2.6y ago
Nice data and super lightweight on site. Good for seeing clickthru data. I also use Postview. The only downside to the plugin is I run my servers at WP Engine and they still call out the CVE related to 5.0.9 which was shortcode. That was fixed two iterations ago but WPE still considers it unfixed. Getting their engineering team to review it has been a month with no progress. That also says something about the security database at WPE for that matter (ie out of date?).
Read on wp.org ↗
Latest updates
via wp.org changelogRecent releases and news for this plugin
- 2026-06-24 Version 5.5.0 Feature: New Goals & Funnels page (slimview6) — define goals and funnels in a modern card layout with pill-segmented funnel tabs, a side drawer for goal create/edit, an overlay builder for funnels, and a destructive-acti 5.5.0
- 2026-05-13 Version 5.4.12 Security: Authenticated SQL injection in the chart AJAX endpoint (slimstat_fetch_chart_data) is now blocked. The chart_data.where parameter is validated against the trusted report registry before reaching the query layer 5.4.12
- 2026-04-17 Version 5.4.11 Fix: Access Log pagination no longer drops the user’s selected custom date range Fix: Auto Refresh setting in Settings → Reports is now honored Fix: Recent panels now show unique items instead of duplicating the same ent 5.4.11
- 2026-04-03 Version 5.4.9 Fix: Scoped sortable handler to Slimstat Customize page only — prevents corrupting WordPress Dashboard widget layout Fix: Use sanitized URI in dashboard widget enqueue condition for consistency 5.4.9
- 2026-03-31 Version 5.4.8 This release fixes remaining tracking issues from the 5.4.x upgrade cycle. If you upgraded from 5.3.x through 5.4.0-5.4.6, this update restores session cookies and client-side tracking automatically. Fix: Session cookies 5.4.8
- 2026-03-23 Version 5.4.6 We heard you — upgrading to 5.4.x broke tracking for many of you. Visitor counts dropped to zero, IPs were masked without your permission, and a consent banner appeared on sites that never asked for one. This release fix 5.4.6
Known vulnerabilities
via Wordfence Intelligence28 disclosed vulnerabilities on record for this plugin, all fixed in the current version. Sites on older versions stay exposed until they update.
- 2026-06-29 CVE-2026-12592 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 5.4.0 Patched in 5.5.0
- 2026-06-17 CVE-2026-54818 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 5.4.11 Patched in 5.4.12
- High · 7.2 SlimStat Analytics <= 5.4.11 - Unauthenticated Stored Cross-Site Scripting via User-Agent Header ↗2026-05-27 CVE-2026-7634 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 5.4.11 Patched in 5.4.12
- 2026-03-18 CVE-2026-1238 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 5.3.5 Patched in 5.4.0
- Medium · 6.5 SlimStat Analytics <= 5.3.1 - Authenticated (Subscriber+) SQL Injection via `args` Parameter ↗2026-02-10 CVE-2025-13431 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 5.3.1 Patched in 5.3.2
- 2026-01-27 CVE-2025-69323 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 5.3.2 Patched in 5.3.3
- High · 7.2 SlimStat Analytics <= 5.3.3 - Unauthenticated Stored Cross-Site Scripting via 'fh' Parameter ↗2026-01-08 CVE-2025-15057 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 5.3.3 Patched in 5.3.4
- 2026-01-08 CVE-2025-15055 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 5.3.4 Patched in 5.3.5
- 2025-12-18 CVE-2025-14151 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 5.3.2 Patched in 5.3.3
- 2024-10-14 CVE-2024-9548 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 5.2.6 Patched in 5.2.7
- Medium · 6.4 SlimStat Analytics <= 5.1.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting ↗2024-02-01 CVE-2024-1073 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 5.1.3 Patched in 5.1.4
- High · 8.8 Slimstat Analytics <= 5.0.9 - Authenticated (Contributor+) Blind SQL Injection via Shortcode ↗2023-09-11 CVE-2023-4598 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 5.0.9 Patched in 5.0.10
- Medium · 6.4 Slimstat Analytics <= 5.0.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ↗2023-08-28 CVE-2023-4597 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 5.0.9 Patched in 5.0.10
- Medium · 4.4 Slimstat Analytics <= 5.0.8 - Authenticated (Administrator+) Stored Cross-Site Scripting via settings ↗2023-08-22 CVE-2023-40676 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 5.0.8 Patched in 5.0.9
- 2023-05-11 CVE-2022-45373 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 5.0.4 Patched in 5.0.5
- 2023-05-11 CVE-2022-45366 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 5.0.4 Patched in 5.0.5
- High · 8.8 Slimstat Analytics <= 4.9.3.3 - Authenticated (Subscriber+) SQL Injection via Shortcode ↗2023-03-30 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 4.9.3.3 Patched in 4.9.3.4
- High · 8.8 Slimstat Analytics <= 4.9.3.2 - Authenticated (Subscriber+) SQL Injection via Shortcode ↗2023-02-23 CVE-2023-0630 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 4.9.3.2 Patched in 4.9.3.3
- 2022-12-19 CVE-2022-4310 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.9.2 Patched in 4.9.3
- 2022-12-12 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.9.2 Patched in 4.9.3
- High · 8.8 Slimstat Analytics <= 4.8.3 - Cross-Site Request Forgery to Stored Cross-Site Scripting ↗2019-05-22 Cross-Site Request Forgery (CSRF) Affects < 4.8.4 Patched in 4.8.4
- 2019-05-21 CVE-2019-15112 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.8 Patched in 4.8.1
- 2015-07-22 CVE-2015-9273 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 4.1.6.1 Patched in 4.1.6.1
- 2015-02-24 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects < 3.9.6 Patched in 3.9.6
- 2015-01-13 CVE-2014-100027 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 3.5.6 Patched in 3.5.6
- Medium · 6.1 Slimstat Analytics <= 3.9.2 - Cross-Site Scripting ↗2015-01-06 CVE-2015-1204 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 3.9.3 Patched in 3.9.3
Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.
CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.
Behavioral tests
via WP HiveAutomated install-time checks, tested on PHP 8.1.12 · WP 7.0.1
Languages
via translate.wordpress.orgTranslated into 57 languages, 0 at 90% or more
Plus 33 more locales with partial translations.
Growth timeline
Install-tier crossings we have observed, and how long each tier took to outgrow
- 2026-06-11 80K+ → 70K+ down after 255 days in tier
- 2025-09-29 90K+ → 80K+ down after 633 days in tier
- 2024-01-05 100K+ → 90K+ down
Competes with
The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).
-
GA Google Analytics – Connect Google Analytics to WordPress 400K+ installs · 4.8★ · 3 shared tags A -
Connect Matomo – Analytics Dashboard for WordPress 60K+ installs · 4.4★ · 3 shared tags A - N NewStatPress 8K+ installs · 4.6★ · 3 shared tags A
-
Better Google Analytics 2K+ installs · 4.1★ · 3 shared tags D
-
Universal Google Analytics (GA3 and GA4) 400+ installs · 4.1★ · 3 shared tags B -
Burst Statistics – Simple WordPress Analytics (Google Analytics Alternative) 200K+ installs · 4.8★ · 2 shared tags A
Embed this report card
Drop a live Pulse card for SlimStat Analytics into a readme, a review or a deck. It updates itself.
<iframe src="https://plugins.wpmayor.com/embed/wp-slimstat" width="480" height="300" style="border:0" loading="lazy" title="SlimStat Analytics — Plugin Pulse"></iframe> SlimStat Analytics: 70K+ active installs, 4.8★ (817 reviews). Plugin Pulse (WP Mayor), as of 2026-08-25. https://plugins.wpmayor.com/plugin/wp-slimstat