A good free one is analog (
www.analog.cx), it's much faster and probably much more secure than Awstats.
I recently read through some of the Awstats source code (I'm a Perl programmer) and it's pretty much a nightmare. I wish this weren't true. It would be difficult to track down security flaws, and indeed a recently-discovered exploit was responsible for major intrusions.
Awstats reports are definitely attractive. If you do use Awstats, you should password protect its directory or even generate static HTML reports and keep the script out of your Web space.