
Author Wordcount Security & Risk Analysis
wordpress.org/plugins/author-wordcountAllows authors to show word counts for works in progress.
Is Author Wordcount Safe to Use in 2026?
Generally Safe
Score 85/100Author Wordcount has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The author-wordcount v1.0 plugin exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of any identified attack surface points, dangerous functions, raw SQL queries, file operations, or external HTTP requests is commendable. Furthermore, the presence of a nonce check and a capability check suggests an awareness of basic WordPress security practices. The plugin's vulnerability history is clean, with no recorded CVEs, which indicates a stable and secure past.
However, a significant concern arises from the low percentage (17%) of properly escaped outputs. With 12 total outputs analyzed, this suggests that a majority of user-facing content within the plugin may be vulnerable to cross-site scripting (XSS) attacks if the input is not sufficiently sanitized elsewhere. While no taint analysis flows with unsanitized paths were detected, this does not negate the risk posed by unescaped output, as the analysis might not have covered all potential input vectors or the specific paths leading to these outputs.
In conclusion, while the plugin benefits from a lack of complex entry points and a clean vulnerability record, the prevalent issue with output escaping is a notable weakness. Developers should prioritize addressing this to prevent potential XSS vulnerabilities. The limited attack surface and the use of prepared statements for the few SQL queries are positive indicators of secure coding principles, but the output escaping needs immediate attention to achieve a robust security profile.
Key Concerns
- Low percentage of properly escaped outputs
Author Wordcount Security Vulnerabilities
Author Wordcount Code Analysis
Output Escaping
Author Wordcount Attack Surface
WordPress Hooks 3
Maintenance & Trust
Author Wordcount Maintenance & Trust
Maintenance Signals
Community Trust
Author Wordcount Alternatives
Just Writing Statistics
just-writing-statistics
Calculate your writing statistics on your WordPress site.
Mooberry Book Manager
mooberry-book-manager
Sell books via Amazon and other retailers directly from your author website with this easy-to-use system. Creates book pages, widgets, and book grids.
Novelist
novelist
Easily organize and display your portfolio of books.
Sunray Author Manager
sunray-author-manager
A versatile plugin for writers to highlight their work, with a carousel slider and bibliography.
Outreachboard
outreachboard
A plugin that helps automate and manage guest author submissions with checklists, syncing, and secure publishing workflows.
Author Wordcount Developer Profile
6 plugins · 70 total installs
How We Detect Author Wordcount
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/author-wordcount/style.cssauthor-wordcount/style.css?ver=HTML / DOM Fingerprints
author_wordcount_elementauthor_wordcount_barid="wordcount_name"id="wordcount_count"id="wordcount_max"id="wordcount_add"id="wordcount_update"id="wordcount_delete"