Bphonetic WordCount Security & Risk Analysis

wordpress.org/plugins/bphonetic-wordcount

Short Description: A lightweight plugin for Classic Editor that adds Bangla & English typing support, word count, and reading time estimation.

0 active installs v1.0 PHP 7.4+ WP 5.8+ Updated Unknown
bphonetic-wordcount
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Bphonetic WordCount Safe to Use in 2026?

Generally Safe

Score 100/100

Bphonetic WordCount has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The bphonetic-wordcount plugin v1.0 exhibits an excellent security posture based on the provided static analysis and vulnerability history. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events significantly reduces the potential attack surface to zero. Furthermore, the code demonstrates strong security practices with zero dangerous functions, 100% of SQL queries using prepared statements, and 100% of output properly escaped. The lack of file operations and external HTTP requests further minimizes common attack vectors. The taint analysis revealing zero flows with unsanitized paths reinforces this positive assessment. The plugin's vulnerability history is also clean, with no recorded CVEs, indicating a history of stable and secure development. The only notable observation is the complete lack of any detected entry points, which, while indicating a secure design, also means there are no explicit capability checks or nonce checks, which are standard WordPress security mechanisms. This could be interpreted as the plugin not requiring any user interaction or privileged access, thus not necessitating these checks, or it could be an oversight if the plugin were to evolve and gain more functionality.

Key Concerns

  • No Nonce checks detected
  • No Capability checks detected
Vulnerabilities
None known

Bphonetic WordCount Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Bphonetic WordCount Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Bphonetic WordCount Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actioninitbphonetic-wordcount.php:24
actionadmin_enqueue_scriptsincludes\BPHOWO_Enqueue.php:8
filterthe_contentincludes\BPHOWO_WordCount.php:9
filterthe_contentincludes\BPHOWO_WordCount.php:10
Maintenance & Trust

Bphonetic WordCount Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedUnknown
PHP min version7.4
Downloads276

Community Trust

Rating0/100
Number of ratings0
Active installs0
Alternatives

Bphonetic WordCount Alternatives

No alternatives data available yet.

Developer Profile

Bphonetic WordCount Developer Profile

Pixoten

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Bphonetic WordCount

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bphonetic-wordcount/assets/js/phonetic.driver.js/wp-content/plugins/bphonetic-wordcount/assets/js/engine.js/wp-content/plugins/bphonetic-wordcount/assets/js/bpwc-quick-tags.js
Script Paths
/wp-content/plugins/bphonetic-wordcount/assets/js/phonetic.driver.js/wp-content/plugins/bphonetic-wordcount/assets/js/engine.js/wp-content/plugins/bphonetic-wordcount/assets/js/bpwc-quick-tags.js
Version Parameters
bphonetic-wordcount/assets/js/phonetic.driver.js?ver=1.0bphonetic-wordcount/assets/js/engine.js?ver=1.0bphonetic-wordcount/assets/js/bpwc-quick-tags.js?ver=1.0

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Bphonetic WordCount