Counter Number Showcase, Fun Facts – WordPress Animated Counter Plugin Security & Risk Analysis

wordpress.org/plugins/counter-number-showcase

Counter Number WordPress Plugin brings you all the powerful Stats Counter features to your wordpress website

10K active installs v1.4.0 PHP + WP 5.0+ Updated Dec 26, 2024
animated-countercountercounter-numberfun-factsstats-counter
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Counter Number Showcase, Fun Facts – WordPress Animated Counter Plugin Safe to Use in 2026?

Generally Safe

Score 92/100

Counter Number Showcase, Fun Facts – WordPress Animated Counter Plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "counter-number-showcase" v1.4.0 plugin exhibits a mixed security posture. On the positive side, it demonstrates strong practices with 100% of its SQL queries using prepared statements and a high percentage of properly escaped output. It also shows a lack of known historical vulnerabilities, suggesting a generally well-maintained codebase.

However, significant concerns arise from the static analysis. The presence of an unprotected AJAX handler represents a critical attack vector, potentially allowing unauthorized actions. Furthermore, the use of the `unserialize` function, even without immediate exploitable taint flows, is a known risk for object injection vulnerabilities if user-controlled data is ever passed to it. The overall security score is impacted by these specific risks, despite the plugin's strengths in other areas.

Key Concerns

  • Unprotected AJAX handler
  • Use of unserialize function
Vulnerabilities
None known

Counter Number Showcase, Fun Facts – WordPress Animated Counter Plugin Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Counter Number Showcase, Fun Facts – WordPress Animated Counter Plugin Release Timeline

v1.4.0Current
v1.3.9
v1.3.8
v1.3.7
v1.3.6
v1.3.5
v1.3.4
v1.3.3
v1.3.2
v1.3.1
v1.3.0
v1.2.9
v1.2.8
v1.2.7
v1.2.6
v1.2.5
v1.2.4
v1.2.3
v1.2.2
v1.2.1
Code Analysis
Analyzed Mar 16, 2026

Counter Number Showcase, Fun Facts – WordPress Animated Counter Plugin Code Analysis

Dangerous Functions
8
Raw SQL Queries
0
0 prepared
Unescaped Output
9
159 escaped
Nonce Checks
2
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

unserialize$Def_Settings = unserialize(get_option('wpsm_counterbox_default_settings'));inc\admin\add-counter-box.php:46
unserialize$Counter_Meta_Settings = unserialize(get_post_meta( $post->ID, 'Counter_Meta_Settings' ,true));inc\admin\add-counter-box.php:47
unserialize$mydemo = unserialize(get_post_meta( $post->ID, 'manisha_demo_data', true));inc\admin\add-counter-box.php:59
unserialize$Counter_Meta_Settings = unserialize(get_post_meta( $PostId, 'Counter_Meta_Settings', true));inc\admin\menu.php:242
unserialize$Def_Settings = unserialize(get_option('wpsm_cns_default_settings'));inc\admin\settings.php:5
unserialize$Counter_Meta_Settings = unserialize(get_post_meta( $PostId, 'Counter_Meta_Settings' ,true));inc\admin\settings.php:6
unserialize$Counter_Meta_Settings = unserialize(get_post_meta( $post_id, 'Counter_Meta_Settings', true));templates\content.php:7
unserialize$mydemo = unserialize(get_post_meta( $post_id, 'manisha_demo_data', true));templates\content.php:21

Output Escaping

95% escaped168 total outputs
Attack Surface
1 unprotected

Counter Number Showcase, Fun Facts – WordPress Animated Counter Plugin Attack Surface

Entry Points2
Unprotected1

AJAX Handlers 1

authwp_ajax_wpsm_cns_dismiss_reviewinc\install\installation.php:94

Shortcodes 1

[COUNTER_NUMBER] templates\shortcode.php:2
WordPress Hooks 12
actionadmin_enqueue_scriptsinc\admin\menu.php:15
actioninitinc\admin\menu.php:18
actionadd_meta_boxesinc\admin\menu.php:19
actionadmin_initinc\admin\menu.php:20
actionsave_postinc\admin\menu.php:21
actionsave_postinc\admin\menu.php:22
filtermanage_counter_numbers_posts_columnsinc\admin\menu.php:35
actionmanage_counter_numbers_posts_custom_columninc\admin\menu.php:36
actionwp_enqueue_scriptsinc\install\installation.php:18
filterwidget_textinc\install\installation.php:19
actionadmin_noticesinc\install\installation.php:21
actionin_admin_headerinc\install\installation.php:259
Maintenance & Trust

Counter Number Showcase, Fun Facts – WordPress Animated Counter Plugin Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedDec 26, 2024
PHP min version
Downloads372K

Community Trust

Rating92/100
Number of ratings190
Active installs10K
Developer Profile

Counter Number Showcase, Fun Facts – WordPress Animated Counter Plugin Developer Profile

wpshopmart

8 plugins · 86K total installs

76
trust score
Avg Security Score
95/100
Avg Patch Time
986 days
View full developer profile
Detection Fingerprints

How We Detect Counter Number Showcase, Fun Facts – WordPress Animated Counter Plugin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/counter-number-showcase/assets/js/color-picker.js/wp-content/plugins/counter-number-showcase/assets/css/panel-style.css/wp-content/plugins/counter-number-showcase/assets/js/media-upload-script.js/wp-content/plugins/counter-number-showcase/assets/css/sidebar.css/wp-content/plugins/counter-number-showcase/assets/css/font-awesome/css/font-awesome.min.css/wp-content/plugins/counter-number-showcase/assets/css/cn_jquery-ui.css/wp-content/plugins/counter-number-showcase/assets/css/bootstrap.css/wp-content/plugins/counter-number-showcase/assets/css/fontawesome-iconpicker.css+18 more

HTML / DOM Fingerprints

CSS Classes
wpsm-cns-review-notice
Data Attributes
wpsm-cns-dismiss-review-noticewpsm-cns-review-out
JS Globals
wpshopmart_cns_directory_url
FAQ

Frequently Asked Questions about Counter Number Showcase, Fun Facts – WordPress Animated Counter Plugin