WP Statistics – Simple, privacy-friendly Google Analytics alternative
by VeronaLabs · Analytics
Also makes 3 other plugins · 677K+ installs across the portfolio →
Get website traffic insights with GDPR/CCPA compliant, privacy-friendly analytics. Includes visitor data, stunning graphs, and no data sharing.
86 health vs 64 average across 1,028 Analytics plugins
Directory ranking optimization
How it's scored →How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.
Excellent listing optimization
Biggest win: Support resolution
To rank higher: Mark more forum threads resolved — the resolved ratio feeds the ranking.
Get the full rank-higher report →Daily downloads
Since 2022-10-05 · 1,421 days · wp.org + Plugin Pulse archive
30-day downloads
Rolling 30-day volume · peaks are release surges
487.8K
now · peak 1.1M
Directory rank vs rivals
wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you
Rating trend
Star average over time · dips mark rough releases
Update activity
How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.
What its installed base runs
via wordpress.orgShare of active installs on each version of this plugin · 63% run the current release. Green is the current release; a big slice on older versions is a user base that has stopped updating.
Estimated active installs
The public count shows “600K+”. Our estimate pins where the real number sits.
Modeled within the band wp.org reports; tightens as we track daily.
Install history · since 2015-03-11 · 1,482 observations
Estimated value
What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.
Est. annual revenue
Est. acquisition value
No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price. The recent download trend is too spiky to read.
Details
Recent reviews
All reviews on wp.org ↗- ★★★★★ Graham Stott1mo ago
A really useful plugin giving a wealth of information on who is visiting your site. Having used the technical support I can say that they are very helpful at resolving issues you may have with the plugin. Definitely recommended. This topic was modified 3 days, 3 hours ago by Graham Stott.
Read on wp.org ↗ - ★★★★★ skorodimos1mo ago
It is very useful application Congratulations
Read on wp.org ↗ - ★★★★★ Gennady Kurushin3mo ago
This is an excellent statistics plugin! It provides essential data in a clear and concise format, which makes it ideal for most websites. No-cookie integration makes it better than many third-party implementations, such as Matomo. Email summaries are simple and useful. Strongly recommend!
Read on wp.org ↗ - ★★★★★ soulx3mo ago
This works fine, and I have used it frequently to analyse how users behave on my page.you get a lot in free mode.
Read on wp.org ↗ - ★★★★★ aikotimmer4mo ago
Great plugin. Works like a charm!
Read on wp.org ↗ - ★★★★★ revelnode4mo ago
I hit the paywall with Jetpack, over 5000 visitors in a month… told I had to pay… Dropped Jetpack entirely. I now use other tools like WP Statistics to monitor my traffic instead.
Read on wp.org ↗ - ★★★★★ sonyamakepeace4mo ago
We installed this plugin yesterday, having been disappointed with other site statistic plugins. This one was the worst of them all. I set a page counter on the blog pages, then logged out, and tried viewing the pages from different parts of the world using our VPN. Not one page shows any visitors. So we uninstalled it. Not only this, but the nags to buy the premium version really got me, when even the basics don’t work. This plugin was even worse than StatCounter, and that’s saying something. Statcounter worked fine on my static sites, when all I needed to do was add some code to the footer.
Read on wp.org ↗ - ★★★★★ ambientblog5mo ago
(Edit 15-04) I have changed my feedback from 2 to 5 stars because of the extensive support (even when I’m a free user) which solved the issue. More details below in the reactions.Original feedback:I was happy with the versatility of this plugin and its many options. It looks and works great! But over time I noticed it was way too flattering in the statistics, especially when I compare the results to Google’s Site Kit. It looks like Statistics count all bots as visits!?! Since I don’t know how to interpret the statistics I deleted the plugin for now. This topic was modified 3 months ago by ambientblog. This topic was modified 3 months ago by ambientblog. This topic was modified 3 months ago by ambientblog. Reason: title corrected
Read on wp.org ↗
Latest updates
via wp.org changelogRecent releases and news for this plugin
- 2026-08-22 Version 14.16.11 New: Bounce Rate in Visitor Insights and a Bounce Rate column in the Entry Pages report. Enhancement: Faster bounce rate calculation. Existing per-content bounce rates may shift slightly. Enhancement: New wp_statistics_o 14.16.11
- 2026-07-25 Version 14.16.10 Fix: Prevented a fatal error on the tracking request when the referrer parameter was sent as an array instead of a single value. Enhancement: General security hardening and internal improvements. 14.16.10
- 2026-07-21 Version 14.16.9 Fix: Content Analytics no longer adds the site-wide historical baseline into each post’s Total Views, so per-post totals are accurate again (issue #1097 ). Fix: Prevented a fatal error on admin load when license validati 14.16.9
- 2026-05-19 Version 14.16.8 Enhancement: Hardened input handling across admin AJAX endpoints, the dynamic query builder, the referrer pipeline, and the GeoIP download URL. Enhancement: Removed the bundled moment.min.js in favor of the copy shipped 14.16.8
- 2026-05-12 Version 14.16.7 Enhancement: Hardened escaping and sanitization in device reports. Enhancement: Tracking endpoints now send noindex and no-cache headers to prevent “ghost pages” in Google Search Console. Fix: Stopped GeoLite2-City backg 14.16.7
- 2026-04-16 Version 14.16.6 Fix: Removed legacy TinyMCE integration that caused “Failed to load plugin” errors in the classic editor, especially with themes like Corvix and Avada. Fix: Excluded browser prefetch and prerender requests that were infl 14.16.6
Known vulnerabilities
via Wordfence Intelligence40 disclosed vulnerabilities on record for this plugin, all fixed in the current version. Sites on older versions stay exposed until they update.
- 2026-08-18 CVE-2026-15780 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 14.16.8 Patched in 14.16.9
- 2026-08-03 CVE-2026-16562 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 14.16.9 Patched in 14.16.10
- 2026-06-01 CVE-2026-48839 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 14.16.6 Patched in 14.16.7
- High · 7.2 WP Statistics <= 14.16.4 - Unauthenticated Stored Cross-Site Scripting via 'utm_source' Parameter ↗2026-04-16 CVE-2026-5231 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 14.16.4 Patched in 14.16.5
- High · 7.2 WP Statistics <= 14.5.4 - Unauthenticated Stored Cross-Site Scripting via User-Agent Header ↗2025-09-26 CVE-2025-9816 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 14.15.4 Patched in 14.15.5
- Medium · 4.3 WP Statistics <= 14.15 - Missing Authorization ↗
- 2024-03-11 CVE-2024-2194 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 14.5 Patched in 14.5.1
- 2023-03-06 CVE-2023-0955 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 13.2.16 Patched in 14.0
- 2023-01-31 CVE-2022-38074 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 13.2.10 Patched in 13.2.11
- 2022-12-27 CVE-2022-4230 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 13.2.8 Patched in 13.2.9
- 2022-09-08 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 13.2.5 Patched in 13.2.6
- Medium · 4.3 WP Statistics <= 13.2.5 - Information Disclosure ↗2022-09-07 Exposure of Sensitive Information to an Unauthorized Actor Affects 13.2.5 Patched in 13.2.6
- Medium · 6.1 WP Statistics <= 13.1.7 - Cross-Site Scripting ↗2022-05-24 CVE-2022-27231 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 13.2.0 Patched in 13.2.0
- 2022-05-11 CVE-2022-1005 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 13.2.2 Patched in 13.2.2
- 2022-02-17 CVE-2022-25307 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 13.1.5 Patched in 13.1.6
- Critical · 9.8 WP Statistics <= 13.1.5 - Unauthenticated Blind SQL Injection via current_page_type ↗2022-02-16 CVE-2022-0651 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 13.1.5 Patched in 13.1.6
- Critical · 9.8 WP Statistics <= 13.1.5 - Unauthenticated SQL Injection ↗2022-02-16 CVE-2022-25148 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 13.1.5 Patched in 13.1.6
- 2022-02-16 CVE-2022-25305 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 13.1.5 Patched in 13.1.6
- 2022-02-16 CVE-2022-25149 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 13.1.5 Patched in 13.1.6
- 2022-02-16 CVE-2022-25306 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 13.1.5 Patched in 13.1.6
- 2022-02-10 CVE-2022-0513 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 13.1.4 Patched in 13.1.5
- 2021-08-30 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 13.0.9 Patched in 13.1
- 2021-05-19 CVE-2021-24340 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects < 13.0.8 Patched in 13.0.8
- High · 7.2 WP Statistics <= 12.6.6.1 - Unauthenticated Stored Cross-Site Scripting via IP Manipulation ↗2019-07-01 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 12.6.6.1 Patched in 12.6.7
- 2019-07-01 CVE-2019-13275 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 12.6.6.1 Patched in 12.6.7
- 2019-05-31 CVE-2019-12566 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 12.6.5 Patched in 12.6.6.1
- 2019-04-09 CVE-2019-10864 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 12.6.3 Patched in 12.6.4
- 2017-07-07 CVE-2017-10991 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 12.0.9 Patched in 12.0.10
- 2017-07-03 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 12.0.8.1 Patched in 12.0.9
- 2017-06-30 CVE-2017-18515 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 12.0.7 Patched in 12.0.8
- 2017-04-13 CVE-2017-2136 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 12.0.4 Patched in 12.0.5
- Medium · 6.1 WP Statistics <= 9.5.1 - Cross-Site Scripting ↗2015-08-10 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 9.5.1 Patched in 9.5.2
- 2015-07-09 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects < 9.4.1 Patched in 9.4.1
- 2015-04-15 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 9.1.3 Patched in 9.1.3
- 2014-12-03 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 8.4 Patched in 8.5
- 2014-11-20 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 8.3.1 Patched in 8.3.1
- Medium · 6.1 WP Statistics <= 2.2.4 - Cross-Site Scripting ↗2012-05-15 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.2.4 Patched in 2.2.5
Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.
CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.
Behavioral tests
via WP HiveAutomated install-time checks, tested on PHP 8.1.12 · WP 7.0.1
Languages
via translate.wordpress.orgTranslated into 54 languages, 8 at 90% or more
Plus 30 more locales with partial translations.
Growth timeline
Install-tier crossings we have observed, and how long each tier took to outgrow
No tier crossings observed yet.
Competes with
The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).
-
WP Visitor Statistics (Real Time Traffic) 20K+ installs · 4.4★ · 4 shared tags A -
Fathom Analytics for WP 10K+ installs · 4.5★ · 3 shared tags B
-
Global Site Tag Tracking 1K+ installs · 3.8★ · 3 shared tags D -
MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) 2M+ installs · 4.5★ · 2 shared tags A
-
GA Google Analytics – Connect Google Analytics to WordPress 400K+ installs · 4.8★ · 2 shared tags A -
ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin) 300K+ installs · 2.5★ · 2 shared tags B
Embed this report card
Drop a live Pulse card for WP Statistics – Simple, privacy-friendly Google Analytics alternative into a readme, a review or a deck. It updates itself.
<iframe src="https://plugins.wpmayor.com/embed/wp-statistics" width="480" height="300" style="border:0" loading="lazy" title="WP Statistics – Simple, privacy-friendly Google Analytics alternative — Plugin Pulse"></iframe> WP Statistics – Simple, privacy-friendly Google Analytics alternative: 600K+ active installs, 4.1★ (757 reviews). Plugin Pulse (WP Mayor), as of 2026-08-25. https://plugins.wpmayor.com/plugin/wp-statistics