
Counter live visitors for WooCommerce Security & Risk Analysis
wordpress.org/plugins/counter-visitor-for-woocommerceShow user count on product
Is Counter live visitors for WooCommerce Safe to Use in 2026?
Generally Safe
Score 98/100Counter live visitors for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.
The plugin "counter-visitor-for-woocommerce" v1.4.0 exhibits a mixed security posture. While it demonstrates good practices in its SQL query handling, utilizing prepared statements for all queries, and includes a reasonable number of nonce and capability checks, there are notable areas of concern. The presence of two unprotected AJAX handlers significantly increases the attack surface, as these can be triggered by unauthenticated users, potentially leading to unintended actions or information disclosure. The static analysis also reveals that only 60% of output is properly escaped, suggesting a potential for cross-site scripting (XSS) vulnerabilities in parts of the code that handle user-supplied data or dynamic content.
The plugin's vulnerability history, with one high-severity CVE related to Path Traversal, raises a flag. Although this vulnerability is currently unpatched, the fact that it's the *only* known CVE and it's marked as unpatched is concerning, even if the date appears to be in the future. This suggests a past weakness that could be exploited if it were to re-emerge or if similar issues exist. The taint analysis showing no unsanitized paths is a positive sign, indicating that critical data flows are likely being handled with care. However, this does not negate the risks identified in the static analysis, particularly the unprotected entry points and incomplete output escaping.
Key Concerns
- Unprotected AJAX handlers
- Improper output escaping (40% unescaped)
- High severity vulnerability (unpatched)
Counter live visitors for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Counter live visitors for WooCommerce <= 1.3.6 - Unauthenticated Arbitrary File Deletion in wcvisitor_get_block
Counter live visitors for WooCommerce Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Counter live visitors for WooCommerce Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 12
Maintenance & Trust
Counter live visitors for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Counter live visitors for WooCommerce Alternatives
Personal Hit Counter
personal-hit-counter
Inform the visitor, below the main content, how many times a specific Page, Post, or WooCommerce Product has been viewed by that visitor
WPS Visitor Counter
wps-visitor-counter
Display website visitor statistics with widget, shortcode, and Gutenberg block support.
Mechanic Visitor Counter
mechanic-visitor-counter
Mechanic Visitor Counter is a widgets which will display the Visitor counter and traffic statistics on WordPress. Some of the features offered include …
XT Visitor Counter
xt-visitor-counter
XT Visitor Counter is a widgets which will display the Visitor counter and traffic statistics on WordPress. Some of the features offered include Today …
Live Visitor Counter
wp-visitors-widget
Wordpress Live Visitor Counter allows you to display how many times a page has been viewed with this simple, fast and easy to use the plugin.
Counter live visitors for WooCommerce Developer Profile
6 plugins · 2K total installs
How We Detect Counter live visitors for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/counter-visitor-for-woocommerce/assets/scripts.js/wp-content/plugins/counter-visitor-for-woocommerce/assets/style.css/wp-content/plugins/counter-visitor-for-woocommerce/assets/fontawesome/all.min.css/wp-content/plugins/counter-visitor-for-woocommerce/assets/scripts.js/wp-content/plugins/counter-visitor-for-woocommerce/assets/fontawesome/all.min.csscounter-visitor-for-woocommerce/assets/scripts.js?ver=counter-visitor-for-woocommerce/assets/style.css?ver=counter-visitor-for-woocommerce/assets/fontawesome/all.min.css?ver=HTML / DOM Fingerprints
WCVisitorConfigWCVisitor<span class="wcvisitor-count">