
Counter-Hits Security & Risk Analysis
wordpress.org/plugins/counter-hitsA simple, easy, fast, adaptive, local, objective counter to visit your site.
Is Counter-Hits Safe to Use in 2026?
Generally Safe
Score 100/100Counter-Hits has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "counter-hits" plugin v2.11 presents a generally good security posture based on the static analysis. The absence of dangerous functions, SQL queries not using prepared statements, and proper output escaping are strong indicators of good development practices. Furthermore, the lack of file operations and external HTTP requests reduces the potential attack surface. The vulnerability history being clean with zero recorded CVEs also suggests a stable and secure codebase.
However, there are some areas of concern. The taint analysis reveals two flows with unsanitized paths. While no critical or high severity issues were flagged, this indicates potential for data manipulation or unintended behavior if these paths are exploited. Additionally, the absence of nonce checks and capability checks on the entry points (specifically the shortcode) is a significant weakness. This means that any user, even those without the necessary permissions, could potentially trigger the shortcode's functionality, leading to unexpected results or information disclosure if the shortcode's logic is not entirely benign.
Key Concerns
- Unsanitized paths in taint analysis
- Missing nonce checks on entry points
- Missing capability checks on entry points
Counter-Hits Security Vulnerabilities
Counter-Hits Code Analysis
Output Escaping
Data Flow Analysis
Counter-Hits Attack Surface
Shortcodes 1
WordPress Hooks 1
Maintenance & Trust
Counter-Hits Maintenance & Trust
Maintenance Signals
Community Trust
Counter-Hits Alternatives
WP-PostViews
wp-postviews
Enables you to display how many times a post/page had been viewed.
Visitor Traffic Real Time Statistics
visitors-traffic-real-time-statistics
This plugin will help you to track your visitors, browsers, operating systems, visits and much more in one dashboard page.
SRS Simple Hits Counter
srs-simple-hits-counter
Simple plugin to count and show a total number of hits (Unique visitors or page-views) to the site without using any third party code.
WP Post Statistics (Visitors & Visits Counter)
wp-post-real-time-statistics
a simple tool to know your post statistics
Pageviews
pageviews
A simple and lightweight pageviews counter for your WordPress posts and pages.
Counter-Hits Developer Profile
15 plugins · 2K total installs
How We Detect Counter-Hits
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/counter-hits/css/style.css/wp-content/plugins/counter-hits/js/script.js/wp-content/plugins/counter-hits/js/script.jscounter-hits/css/style.css?ver=counter-hits/js/script.js?ver=HTML / DOM Fingerprints
wpgear_counter_hits<span class='wpgear_counter_hits'>