Block Metrics – Animated State Counter Security & Risk Analysis

wordpress.org/plugins/block-metrics-animated-state-counter

A easy way to display states counter in a easy and interesting way.

20 active installs v1.0.0 PHP 7.4+ WP 6.0+ Updated Dec 15, 2025
animated-countercounter-statescountersnumber-counter-block
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Block Metrics – Animated State Counter Safe to Use in 2026?

Generally Safe

Score 100/100

Block Metrics – Animated State Counter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The 'block-metrics-animated-state-counter' plugin v1.0.0 exhibits a generally strong security posture based on the provided static analysis. It correctly utilizes prepared statements for all SQL queries, ensures all output is properly escaped, and implements nonce checks for its single AJAX handler. The absence of dangerous functions, file operations, and critical taint flows is also a significant positive indicator. The plugin also has no recorded vulnerability history, suggesting a history of secure development or minimal exposure. However, a notable concern is the complete lack of capability checks on its AJAX handler. While a nonce check provides a layer of protection against CSRF attacks, the absence of role-based access control means any authenticated user could potentially interact with this entry point, regardless of their administrative privileges. This could be a weakness if the AJAX handler performs sensitive operations or exposes protected data.

Key Concerns

  • Missing capability checks on AJAX handler
Vulnerabilities
None known

Block Metrics – Animated State Counter Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Block Metrics – Animated State Counter Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
5 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

100% escaped5 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
zlgcb_handle_deactivation_form (includes\deactivation-feedback.php:24)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Block Metrics – Animated State Counter Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_zlgcb_handle_deactivation_formincludes\deactivation-feedback.php:17
WordPress Hooks 3
actionadmin_noticesincludes\deactivation-feedback.php:20
actioninitzlgcb-counter-block.php:41
actionadmin_enqueue_scriptszlgcb-counter-block.php:44
Maintenance & Trust

Block Metrics – Animated State Counter Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 15, 2025
PHP min version7.4
Downloads1K

Community Trust

Rating100/100
Number of ratings2
Active installs20
Developer Profile

Block Metrics – Animated State Counter Developer Profile

Maulik Vora

5 plugins · 10K total installs

79
trust score
Avg Security Score
100/100
Avg Patch Time
123 days
View full developer profile
Detection Fingerprints

How We Detect Block Metrics – Animated State Counter

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/block-metrics-animated-state-counter/block/block.js/wp-content/plugins/block-metrics-animated-state-counter/public/css/style.css/wp-content/plugins/block-metrics-animated-state-counter/public/js/frontend.js/wp-content/plugins/block-metrics-animated-state-counter/admin/css/editor.css/wp-content/plugins/block-metrics-animated-state-counter/admin/js/admin.js
Script Paths
block/block.jspublic/js/frontend.jsadmin/js/admin.js
Version Parameters
block-metrics-animated-state-counter/block/block.js?ver=block-metrics-animated-state-counter/public/css/style.css?ver=block-metrics-animated-state-counter/public/js/frontend.js?ver=block-metrics-animated-state-counter/admin/css/editor.css?ver=block-metrics-animated-state-counter/admin/js/admin.js?ver=

HTML / DOM Fingerprints

JS Globals
ajax_obj
FAQ

Frequently Asked Questions about Block Metrics – Animated State Counter