Counter Number Showcase, Fun Facts – WordPress Animated Counter Plugin Security & Risk Analysis

wordpress.org/plugins/counter-number-showcase

Counter Number WordPress Plugin brings you all the powerful Stats Counter features to your wordpress website

10K active installs v1.4.0 PHP + WP 5.0+ Updated Dec 26, 2024
animated-countercountercounter-numberfun-factsstats-counter
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Counter Number Showcase, Fun Facts – WordPress Animated Counter Plugin Safe to Use in 2026?

Generally Safe

Score 92/100

Counter Number Showcase, Fun Facts – WordPress Animated Counter Plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "counter-number-showcase" v1.4.0 plugin exhibits a mixed security posture. On the positive side, it demonstrates strong practices with 100% of its SQL queries using prepared statements and a high percentage of properly escaped output. It also shows a lack of known historical vulnerabilities, suggesting a generally well-maintained codebase.

However, significant concerns arise from the static analysis. The presence of an unprotected AJAX handler represents a critical attack vector, potentially allowing unauthorized actions. Furthermore, the use of the `unserialize` function, even without immediate exploitable taint flows, is a known risk for object injection vulnerabilities if user-controlled data is ever passed to it. The overall security score is impacted by these specific risks, despite the plugin's strengths in other areas.

Key Concerns

  • Unprotected AJAX handler
  • Use of unserialize function
Vulnerabilities
None known

Counter Number Showcase, Fun Facts – WordPress Animated Counter Plugin Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Counter Number Showcase, Fun Facts – WordPress Animated Counter Plugin Code Analysis

Dangerous Functions
8
Raw SQL Queries
0
0 prepared
Unescaped Output
9
159 escaped
Nonce Checks
2
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

unserialize$Def_Settings = unserialize(get_option('wpsm_counterbox_default_settings'));inc\admin\add-counter-box.php:46
unserialize$Counter_Meta_Settings = unserialize(get_post_meta( $post->ID, 'Counter_Meta_Settings' ,true));inc\admin\add-counter-box.php:47
unserialize$mydemo = unserialize(get_post_meta( $post->ID, 'manisha_demo_data', true));inc\admin\add-counter-box.php:59
unserialize$Counter_Meta_Settings = unserialize(get_post_meta( $PostId, 'Counter_Meta_Settings', true));inc\admin\menu.php:242
unserialize$Def_Settings = unserialize(get_option('wpsm_cns_default_settings'));inc\admin\settings.php:5
unserialize$Counter_Meta_Settings = unserialize(get_post_meta( $PostId, 'Counter_Meta_Settings' ,true));inc\admin\settings.php:6
unserialize$Counter_Meta_Settings = unserialize(get_post_meta( $post_id, 'Counter_Meta_Settings', true));templates\content.php:7
unserialize$mydemo = unserialize(get_post_meta( $post_id, 'manisha_demo_data', true));templates\content.php:21

Output Escaping

95% escaped168 total outputs
Attack Surface
1 unprotected

Counter Number Showcase, Fun Facts – WordPress Animated Counter Plugin Attack Surface

Entry Points2
Unprotected1

AJAX Handlers 1

authwp_ajax_wpsm_cns_dismiss_reviewinc\install\installation.php:94

Shortcodes 1

[COUNTER_NUMBER] templates\shortcode.php:2
WordPress Hooks 12
actionadmin_enqueue_scriptsinc\admin\menu.php:15
actioninitinc\admin\menu.php:18
actionadd_meta_boxesinc\admin\menu.php:19
actionadmin_initinc\admin\menu.php:20
actionsave_postinc\admin\menu.php:21
actionsave_postinc\admin\menu.php:22
filtermanage_counter_numbers_posts_columnsinc\admin\menu.php:35
actionmanage_counter_numbers_posts_custom_columninc\admin\menu.php:36
actionwp_enqueue_scriptsinc\install\installation.php:18
filterwidget_textinc\install\installation.php:19
actionadmin_noticesinc\install\installation.php:21
actionin_admin_headerinc\install\installation.php:259
Maintenance & Trust

Counter Number Showcase, Fun Facts – WordPress Animated Counter Plugin Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedDec 26, 2024
PHP min version
Downloads371K

Community Trust

Rating92/100
Number of ratings190
Active installs10K
Developer Profile

Counter Number Showcase, Fun Facts – WordPress Animated Counter Plugin Developer Profile

wpshopmart

8 plugins · 86K total installs

76
trust score
Avg Security Score
95/100
Avg Patch Time
986 days
View full developer profile
Detection Fingerprints

How We Detect Counter Number Showcase, Fun Facts – WordPress Animated Counter Plugin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/counter-number-showcase/assets/js/color-picker.js/wp-content/plugins/counter-number-showcase/assets/css/panel-style.css/wp-content/plugins/counter-number-showcase/assets/js/media-upload-script.js/wp-content/plugins/counter-number-showcase/assets/css/sidebar.css/wp-content/plugins/counter-number-showcase/assets/css/font-awesome/css/font-awesome.min.css/wp-content/plugins/counter-number-showcase/assets/css/cn_jquery-ui.css/wp-content/plugins/counter-number-showcase/assets/css/bootstrap.css/wp-content/plugins/counter-number-showcase/assets/css/fontawesome-iconpicker.css+18 more

HTML / DOM Fingerprints

CSS Classes
wpsm-cns-review-notice
Data Attributes
wpsm-cns-dismiss-review-noticewpsm-cns-review-out
JS Globals
wpshopmart_cns_directory_url
FAQ

Frequently Asked Questions about Counter Number Showcase, Fun Facts – WordPress Animated Counter Plugin