AB Post View Counter Security & Risk Analysis

wordpress.org/plugins/ab-post-view-counter

Plugin that count post/page views.

0 active installs v1.14 PHP + WP 3.8+ Updated May 6, 2017
counterpagepostview
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is AB Post View Counter Safe to Use in 2026?

Generally Safe

Score 85/100

AB Post View Counter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The "ab-post-view-counter" plugin v1.14 exhibits a generally good security posture based on the provided static analysis. The absence of dangerous functions, SQL queries requiring preparation, file operations, and external HTTP requests is a positive indicator. Furthermore, the plugin has no recorded vulnerability history, suggesting a history of stable and secure development.

However, a significant concern arises from the output escaping. With one total output and 0% properly escaped, there is a clear risk of Cross-Site Scripting (XSS) vulnerabilities. Any dynamic data displayed to users, if not properly sanitized, could be exploited by attackers. The lack of nonce and capability checks, while not immediately exploitable without identified entry points, means that if any entry points were to be introduced or discovered, they would lack crucial security protections.

In conclusion, while the plugin appears to be built on a secure foundation with no known historical vulnerabilities, the critical oversight in output escaping presents a tangible and immediate risk. The absence of specific vulnerability types in its history is encouraging, but it does not negate the potential for exploits due to poor output handling. Addressing the unescaped output is paramount for improving the plugin's security.

Key Concerns

  • 0% output escaping
  • 0 capability checks
  • 0 nonce checks
Vulnerabilities
None known

AB Post View Counter Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

AB Post View Counter Release Timeline

v1.15
v1.14Current
v1.13
v1.12
v1.11
v1.10
v1.0
Code Analysis
Analyzed Apr 16, 2026

AB Post View Counter Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped1 total outputs
Attack Surface

AB Post View Counter Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionadmin_initab-post-count-plugin.php:114
actionadmin_menuab-post-count-plugin.php:115
actionwp_headab-post-count-plugin.php:116
filterthe_contentab-post-count-plugin.php:117
filtermanage_pages_columnsab-post-count-plugin.php:118
filtermanage_posts_columnsab-post-count-plugin.php:119
actionmanage_posts_custom_columnab-post-count-plugin.php:120
actionmanage_pages_custom_columnab-post-count-plugin.php:121
Maintenance & Trust

AB Post View Counter Maintenance & Trust

Maintenance Signals

WordPress version tested4.8.28
Last updatedMay 6, 2017
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

AB Post View Counter Developer Profile

abjelosevic

5 plugins · 30 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect AB Post View Counter

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

Shortcode Output
Read count:
FAQ

Frequently Asked Questions about AB Post View Counter