Counter Ecl Security & Risk Analysis

wordpress.org/plugins/counter-ecl

Making WordPress web counter widget and cookie Law.

200 active installs v1.5 PHP + WP 4.1+ Updated Sep 23, 2016
bootstrapcountermultisiteresponsivewidget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Counter Ecl Safe to Use in 2026?

Generally Safe

Score 85/100

Counter Ecl has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The "counter-ecl" plugin version 1.5 exhibits a generally strong security posture based on the static analysis provided. The absence of dangerous functions, external HTTP requests, file operations, and the use of prepared statements for all SQL queries are positive indicators. Furthermore, the plugin has no recorded vulnerability history, suggesting a history of secure development or a lack of public disclosure of past issues. However, a significant concern arises from the low percentage of properly escaped output (18%). This indicates a substantial risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data or internal data displayed to users may not be sufficiently sanitized, allowing for malicious script injection. The plugin also lacks explicit nonce and capability checks, which, while not directly indicated as exploitable in this analysis due to the absence of AJAX/REST endpoints and cron jobs with unauthenticated access, represents a potential weakness if the attack surface were to expand in future versions or if the single shortcode is used in contexts that warrant authorization.

Key Concerns

  • Low output escaping rate (18%)
  • Missing nonce checks on entry points
  • Missing capability checks on entry points
Vulnerabilities
None known

Counter Ecl Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Counter Ecl Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
62
14 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

18% escaped76 total outputs
Attack Surface

Counter Ecl Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[counter_ecl] contador.php:747
WordPress Hooks 10
actionwp_enqueue_scriptscontador.php:134
filterplugin_action_linkscontador.php:153
actionplugins_loadedcontador.php:166
actionwp_loadedcontador.php:184
actionadmin_initcontador.php:224
actionadmin_menucontador.php:226
actionwidgets_initcontador.php:724
actioninitcontador.php:750
actionwp_footercontador.php:797
actionwp_footercontador.php:814
Maintenance & Trust

Counter Ecl Maintenance & Trust

Maintenance Signals

WordPress version tested4.8.28
Last updatedSep 23, 2016
PHP min version
Downloads7K

Community Trust

Rating0/100
Number of ratings0
Active installs200
Developer Profile

Counter Ecl Developer Profile

enriquecerda

1 plugin · 200 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Counter Ecl

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/counter-ecl/css/bootstrap-theme.min.css/wp-content/plugins/counter-ecl/css/bootstrap.min.css/wp-content/plugins/counter-ecl/css/counter-ecl.css/wp-content/plugins/counter-ecl/js/counter-ecl.js
Script Paths
/wp-content/plugins/counter-ecl/js/counter-ecl.js
Version Parameters
counter-ecl/css/bootstrap-theme.min.css?ver=counter-ecl/css/bootstrap.min.css?ver=counter-ecl/css/counter-ecl.css?ver=counter-ecl/js/counter-ecl.js?ver=

HTML / DOM Fingerprints

CSS Classes
ecl-cont-bootstrapecl-cont-bootstrap-themeecl-cont-cssecl-cont-js
HTML Comments
Copyright 2015 Enrique CerdaThis program is free software; you can redistribute it and/or modifyThis program is distributed in the hope that it will be useful,You should have received a copy of the GNU General Public License+8 more
Data Attributes
name="counter_ecl"id="counter_ecl"name="counter_ecl_time"name="counter_ecl_message_active"name="counter_ecl_message"name="counter_ecl_color_text"+5 more
JS Globals
ecl_cont_visitedecl_cont_messageecl_cont_oldecl_domain
FAQ

Frequently Asked Questions about Counter Ecl