It is a common misconception that the stats directory is protected because it is usually accessed through the CNC - but I found out only after bookmarking my actual stats directory and not being asked for a password. I have since protected it.
I do the exact same thing - I have found a lot of warez sites that way - they link to me and I find them in the stats. Or someone may just happen to click a bookmark or type the URL to my site while at that page. But here's another scenario:
You are looking at YOUR stats and follow some links, see who's linking. Now that person has your stats page as a referer URL in THEIR stats

So they follow the link and see your stats and follow links from there out of curiosity - then you follow to their stats - it goes on forever.
And the worst part is that a search engine bot can follow links and eventually end up at your stats. Then they see ALL your URL's and index them. Hidden or not (as long as they are not protected with .htaccess that is). All in all, if you don't want the world to see something it needs to be password protected.
Always remember, it is the
World wide web
------------------
Justin Nelson
FutureQuest Support