
Simple Counter Security & Risk Analysis
wordpress.org/plugins/abwp-simple-counterThe installation of the counter of Yandex.Metrics and Google Analytics on the website without editing the files of the selected theme.
Is Simple Counter Safe to Use in 2026?
Mostly Safe
Score 71/100Simple Counter is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved. Keep it updated.
The "abwp-simple-counter" plugin exhibits a mixed security posture. On the positive side, it has a very small attack surface with only one shortcode and no AJAX handlers or REST API routes. All SQL queries are properly prepared, and there are no detected file operations or external HTTP requests. The presence of a capability check on its sole entry point is also a good sign.
However, significant concerns arise from the lack of output escaping. With 18 outputs and 0% properly escaped, this plugin is highly vulnerable to Cross-Site Scripting (XSS) attacks. The absence of nonce checks on any potential entry points further exacerbates this risk, as it allows for potential Cross-Site Request Forgery (CSRF) if malicious actors can trigger actions. The vulnerability history, which includes a known medium-severity XSS vulnerability that remains unpatched, strongly reinforces these concerns.
In conclusion, while the plugin demonstrates some good security practices like prepared SQL statements, the critical lack of output escaping and the unpatched XSS vulnerability present a substantial risk. The developer needs to address output sanitization and ensure all known vulnerabilities are patched to improve the plugin's security.
Key Concerns
- Unpatched Medium CVE
- 100% Unescaped Output
- 0 Nonce Checks
Simple Counter Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Simple Counter <= 1.0.3 - Authenticated (Administrator+) Stored Cross-Site Scripting via settings
Simple Counter Code Analysis
Output Escaping
Simple Counter Attack Surface
Shortcodes 1
WordPress Hooks 7
Maintenance & Trust
Simple Counter Maintenance & Trust
Maintenance Signals
Community Trust
Simple Counter Alternatives
WT Yandex Metrika
wt-yandex-metrika
Простое добавление на сайт счетчика Яндекс.Метрика
Easy Yandex Metrica
easy-yandex-metrica
Easily add statistics display Yandex Metrica to the Wordpress admin panel.
Fast Yandex Metrika
fast-yandex-metrika
Plugin for configuring the counter and Yandex Metrica goals.
Yandex.Metrica
wp-yandex-metrika
The free official Yandex.Metrica plugin for WordPress.
Yandex Metrica
yandex-metrica
Easy way to use Yandex Metrica on your WordPress site.
Simple Counter Developer Profile
2 plugins · 2K total installs
How We Detect Simple Counter
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
wrap[simple-counter id="metrika"][simple-counter id="analytics"]