
Click Counter by Simple Tools Security & Risk Analysis
wordpress.org/plugins/click-counterAdvanced click tracking for any CSS selector. Analytics, charts, goals, CSV export, visual picker, and more.
Is Click Counter by Simple Tools Safe to Use in 2026?
Generally Safe
Score 100/100Click Counter by Simple Tools has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'click-counter' plugin version 1.0.3 exhibits a generally strong security posture, with excellent adherence to secure coding practices such as the exclusive use of prepared statements for SQL queries and a high percentage of properly escaped output. The absence of known CVEs and a history of no recorded vulnerabilities further reinforces this positive assessment. All identified entry points, including AJAX handlers, shortcodes, and cron events, appear to be protected by appropriate authorization and nonce checks, indicating a deliberate effort to prevent unauthorized access and actions.
Despite the overall strong security, a single high-severity taint flow with an unsanitized path represents a potential concern. While the static analysis did not uncover any directly exploitable vulnerabilities from this, it signifies an area where user-supplied input might not be adequately validated or neutralized before being used in a sensitive operation, which could lead to unexpected behavior or potentially be chained with other factors to exploit a weakness. The plugin also makes an external HTTP request, which, while not inherently a vulnerability, is a potential attack vector if the target endpoint is compromised or if sensitive data is sent unencrypted.
In conclusion, 'click-counter' v1.0.3 is a well-developed plugin with robust security fundamentals. The primary area requiring attention is the identified unsanitized path in the taint analysis. Addressing this specific issue would further solidify the plugin's security and mitigate the remaining identified risk.
Key Concerns
- High severity taint flow with unsanitized path
- External HTTP request
Click Counter by Simple Tools Security Vulnerabilities
Click Counter by Simple Tools Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Click Counter by Simple Tools Attack Surface
AJAX Handlers 12
Shortcodes 1
WordPress Hooks 9
Scheduled Events 1
Maintenance & Trust
Click Counter by Simple Tools Maintenance & Trust
Maintenance Signals
Community Trust
Click Counter by Simple Tools Alternatives
Epic Tracking
epic-tracking
Easy event tracking for WordPress. Point, click, and track — no code, no tag managers, no third-party scripts.
GA Google Analytics – Connect Google Analytics to WordPress
ga-google-analytics
Adds Google Analytics tracking code to your WordPress site. Supports many tracking features.
SlimStat Analytics
wp-slimstat
The leading web analytics plugin for WordPress
Connect Matomo – Analytics Dashboard for WordPress
wp-piwik
Adds Matomo (former Piwik) statistics to your WordPress dashboard and is also able to add the Matomo Tracking Code to your blog.
Pixel Manager for WooCommerce – Conversion Tracking, Google Ads, GA4, TikTok, Dynamic Remarketing
woocommerce-google-adwords-conversion-tracking-tag
Conversion tracking for WooCommerce. Google Ads, GA4, Meta/Facebook Pixel, TikTok & more. Recover 30% more conversions with server-side tracking!
Click Counter by Simple Tools Developer Profile
6 plugins · 180 total installs
How We Detect Click Counter by Simple Tools
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/click-counter/assets/css/chart.css/wp-content/plugins/click-counter/assets/css/editor.css/wp-content/plugins/click-counter/assets/css/frontend.css/wp-content/plugins/click-counter/assets/css/admin.css/wp-content/plugins/click-counter/assets/js/chart.js/wp-content/plugins/click-counter/assets/js/editor.js/wp-content/plugins/click-counter/assets/js/frontend.js/wp-content/plugins/click-counter/assets/js/admin.jsassets/js/frontend.jsassets/js/editor.jsassets/js/admin.jsassets/js/chart.jsclick-counter/assets/css/chart.css?ver=click-counter/assets/css/editor.css?ver=click-counter/assets/css/frontend.css?ver=click-counter/assets/css/admin.css?ver=click-counter/assets/js/chart.js?ver=click-counter/assets/js/editor.js?ver=click-counter/assets/js/frontend.js?ver=click-counter/assets/js/admin.js?ver=HTML / DOM Fingerprints
clicco-chartclicco-admin-wrapclicco-goal-rowCLICCO_FEEDBACK_URLCLICCO_TABLECLICCO_SELECTORS_TABLECLICCO_VERSION+4 moredata-clicco-selectordata-clicco-nameclicco_chart_dataclicco_chart_labelsclicco_chart_configclicco_chart_instanceclicco_editor_settingsclicco_editor_post_id+1 more/wp-json/ssp-feedback/v1/submit