Hitsteps Web Analytics

hitsteps-visitor-manager · by hitsteps · wordpress.org ↗ · SVN ↗
Active installs
800
Current version
5.93
Added
2013-11-19
Last updated
2026-06-20 (9d ago)
First seen by beacon
2mo ago
Total downloads
135,267

Statistics

2024-06-17 → 2026-06-15 · 729 days
Downloads today
10
7-day total 97
Week over week
▼ -79%
vs prior 7 days
30-day trend
flat
▼ -29% MoM
Abandonment
○○○○○
healthy
Downloads/day Linear trend
48036024012002024-062024-102025-022025-062025-102026-022026-06
43332521710802026-032026-042026-042026-052026-052026-06
3112331567802026-052026-052026-052026-062026-062026-06

Active versions

5.915.92other
5.91 · 39.7%5.92 · 36.1%other · 11.3%5.88 · 7.7%5.90 · 5.3%

Ratings

5★
5
4★
0
3★
0
2★
0
1★
2

Support: 0/0 resolved

Alerts (0)

No open alerts.

Show 1 resolved alert
Critical code_pattern Resolved · vendor_failover_ips_hitsteps_analytics 2026-05-08 09:56:52 (1mo ago)
Slughitsteps-visitor-manager
Patternhardcoded_ip_url
Kindbuiltin
Version5.91
Hit count2
First hit
File
api.payload.php
Line
4
Snippet
$hitsteps_public_web_api_receiver1="http://144.76.44.111/api/query.php";
Explanationplugin source hardcodes a raw IPv4 URL (e.g. `https://94.156.79.8/...`) — legitimate plugins use DNS hostnames because IPs change. Hardcoded IPs in plugin code are almost always either dev leftovers or attacker C2 infrastructure. The June 2024 social-warfare keylogger (audit #14) used `https://94.156.79.8/sc-top.js` for the JS payload host, `/AddSites` for victim registration, `/CMSUsers` for filesystem-recon exfil. Operator infrastructure on raw IPs avoids domain registration / RDAP detection paths. Post-filtered to skip RFC1918/loopback/link-local ranges and `vendor/`/`tests/` paths.
View raw JSON
{
    "slug": "hitsteps-visitor-manager",
    "pattern": "hardcoded_ip_url",
    "kind": "builtin",
    "version": "5.91",
    "hit_count": 2,
    "first_hit": {
        "file": "api.payload.php",
        "line": 4,
        "snippet": "$hitsteps_public_web_api_receiver1=\"http://144.76.44.111/api/query.php\";"
    },
    "explanation": "plugin source hardcodes a raw IPv4 URL (e.g. `https://94.156.79.8/...`) \u2014 legitimate plugins use DNS hostnames because IPs change. Hardcoded IPs in plugin code are almost always either dev leftovers or attacker C2 infrastructure. The June 2024 social-warfare keylogger (audit #14) used `https://94.156.79.8/sc-top.js` for the JS payload host, `/AddSites` for victim registration, `/CMSUsers` for filesystem-recon exfil. Operator infrastructure on raw IPs avoids domain registration / RDAP detection paths. Post-filtered to skip RFC1918/loopback/link-local ranges and `vendor/`/`tests/` paths."
}

SVN committers (2)

Accounts with actual commit access to hitsteps-visitor-manager on plugins.svn.wordpress.org, reconstructed from svn log. This is the list that matters for ownership changes — not the readme contributors.

Committer Member since Commits First commit Latest commit
Hitsteps Young account 2013-11-18 2 2013-11-19 · r806645 2026-06-04 · r3560614
plugin-master 2007-03-09 1 2013-11-19 · r806570 2013-11-19 · r806570

Readme contributors (1)

Names the plugin's readme declares as contributors. A soft signal — anyone can be listed. The SVN access column is the ground-truth cross-reference: does this contributor actually commit code?

Contributor Member since SVN access Status
Hitsteps 2013-11-18 2 commits Active

Versions (100 most recent)

Version Released Download
5.93 zip
5.92 2026-06-04 · 25d ago zip
5.91 2025-05-09 · 1y ago zip
5.90 2025-02-14 · 1y ago zip
5.89 2025-01-12 · 1y ago zip
5.88 2024-03-03 · 2y ago zip
5.87 2023-10-14 · 2y ago zip
5.86 2023-10-08 · 2y ago zip
5.85 2023-05-22 · 3y ago zip
5.84 2023-03-09 · 3y ago zip
5.83 2022-12-18 · 3y ago zip
5.82 2022-05-14 · 4y ago zip
5.81 2022-05-06 · 4y ago zip
5.80 2022-04-13 · 4y ago zip
5.79 2022-04-12 · 4y ago zip
5.71 2022-04-12 · 4y ago zip
5.72 2022-04-12 · 4y ago zip
5.78 2021-07-18 · 4y ago zip
5.77 2021-01-30 · 5y ago zip
5.76 2020-10-17 · 5y ago zip
5.75 2020-04-12 · 6y ago zip
5.74 2019-12-20 · 6y ago zip
5.73 2019-10-11 · 6y ago zip
5.70 2019-08-06 · 6y ago zip
5.69 2019-03-28 · 7y ago zip
5.68 2019-03-24 · 7y ago zip
5.67 2019-03-13 · 7y ago zip
5.66 2019-03-10 · 7y ago zip
5.65 2019-03-04 · 7y ago zip
5.64 2019-03-03 · 7y ago zip
5.63 2019-01-06 · 7y ago zip
5.62 2018-12-07 · 7y ago zip
5.61 2018-12-04 · 7y ago zip
5.60 2018-11-11 · 7y ago zip
5.59 2018-11-10 · 7y ago zip
5.58 2018-11-04 · 7y ago zip
5.57 2018-10-24 · 7y ago zip
5.56 2018-10-18 · 7y ago zip
5.55 2018-10-04 · 7y ago zip
5.54 2018-09-03 · 7y ago zip
5.53 2018-06-18 · 8y ago zip
5.52 2018-06-07 · 8y ago zip
5.51 2018-06-03 · 8y ago zip
5.50 2018-05-23 · 8y ago zip
5.49 2018-05-22 · 8y ago zip
5.48 2018-05-20 · 8y ago zip
5.47 2018-05-16 · 8y ago zip
5.46 2018-05-13 · 8y ago zip
5.45 2018-05-12 · 8y ago zip
5.44 2018-03-07 · 8y ago zip
5.43 2018-03-06 · 8y ago zip
5.42 2017-09-24 · 8y ago zip
5.41 2017-08-29 · 8y ago zip
5.40 2017-08-22 · 8y ago zip
5.39 2017-07-30 · 8y ago zip
5.38 2017-05-06 · 9y ago zip
5.37 2017-04-16 · 9y ago zip
5.36 2017-03-07 · 9y ago zip
5.35 2017-01-31 · 9y ago zip
5.34 2017-01-18 · 9y ago zip
5.33 2017-01-07 · 9y ago zip
5.32 2016-11-25 · 9y ago zip
5.31 2016-10-28 · 9y ago zip
5.30 2016-09-30 · 9y ago zip
5.29 2016-09-16 · 9y ago zip
5.28 2016-09-15 · 9y ago zip
5.27 2016-09-06 · 9y ago zip
3.00 2016-08-30 · 9y ago zip
3.95 2016-08-30 · 9y ago zip
5.26 2016-08-30 · 9y ago zip
5.25 2016-08-18 · 9y ago zip
5.24 2016-08-01 · 9y ago zip
5.23 2016-07-26 · 9y ago zip
5.21 2016-07-24 · 9y ago zip
5.22 2016-07-24 · 9y ago zip
5.20 2016-07-12 · 9y ago zip
5.19 2016-07-08 · 9y ago zip
5.18 2016-06-30 · 10y ago zip
5.17 2016-06-22 · 10y ago zip
5.16 2016-06-20 · 10y ago zip
5.14 2016-06-06 · 10y ago zip
5.13 2016-05-16 · 10y ago zip
5.12 2016-04-16 · 10y ago zip
5.11 2016-04-05 · 10y ago zip
5.09 2016-03-28 · 10y ago zip
5.08 2016-03-26 · 10y ago zip
5.07 2016-03-19 · 10y ago zip
5.06 2016-03-08 · 10y ago zip
5.04 2016-03-06 · 10y ago zip
5.05 2016-03-06 · 10y ago zip
5.03 2016-02-20 · 10y ago zip
5.02 2016-02-15 · 10y ago zip
5.01 2016-02-11 · 10y ago zip
5.00 2016-02-07 · 10y ago zip
4.99 2016-02-02 · 10y ago zip
4.98 2016-01-30 · 10y ago zip
4.97 2016-01-25 · 10y ago zip
4.96 2016-01-21 · 10y ago zip
4.95 2016-01-12 · 10y ago zip
4.94 2016-01-06 · 10y ago zip