Countera Security & Risk Analysis

wordpress.org/plugins/countera

Track post view count by user and date for better insights.

10 active installs v1.0.0 PHP 8.1.2+ WP 5.0.0+ Updated May 19, 2024
analyticscsv-exportpost-viewsstatisticsview-counter
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Countera Safe to Use in 2026?

Generally Safe

Score 92/100

Countera has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The 'countera' plugin version 1.0.0 presents a mixed security posture. On the positive side, it demonstrates good practices with a high percentage of SQL queries using prepared statements and a very high rate of properly escaped output. The absence of file operations, external HTTP requests, and recorded vulnerabilities in its history are also strong indicators of a generally secure codebase.

However, significant concerns arise from the static analysis. The plugin exposes two AJAX handlers, both of which lack authentication checks. This creates a substantial attack surface that could be exploited by unauthenticated users. While no critical taint flows or dangerous functions were identified, the unprotected AJAX endpoints are a clear vulnerability. The plugin also bundles DataTables, which could potentially introduce risks if not kept up-to-date, though no specific version information is provided to assess this.

In conclusion, while 'countera' v1.0.0 benefits from secure coding practices in many areas and a clean vulnerability history, the presence of two unprotected AJAX endpoints is a critical flaw that significantly increases its risk profile. Addressing these unauthenticated entry points should be the highest priority.

Key Concerns

  • AJAX handlers without auth checks
  • Bundled library (DataTables)
Vulnerabilities
None known

Countera Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Countera Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
9 prepared
Unescaped Output
2
33 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

DataTables

SQL Query Safety

82% prepared11 total queries

Output Escaping

94% escaped35 total outputs
Attack Surface
2 unprotected

Countera Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_countera_get_user_post_views_countinc\core\class-init.php:107
authwp_ajax_countera_bulk_actioninc\core\class-init.php:108
WordPress Hooks 6
actionplugins_loadedinc\core\class-init.php:93
actionadmin_menuinc\core\class-init.php:104
actionadmin_enqueue_scriptsinc\core\class-init.php:105
actionadmin_enqueue_scriptsinc\core\class-init.php:106
actionadmin_initinc\core\class-init.php:109
actionwp_headinc\core\class-init.php:120
Maintenance & Trust

Countera Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedMay 19, 2024
PHP min version8.1.2
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Countera Developer Profile

extendmate.com

2 plugins · 10 total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Countera

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/countera/inc/admin/css/countera-admin-style.css/wp-content/plugins/countera/inc/admin/js/countera-admin-script.js
Script Paths
/wp-content/plugins/countera/inc/admin/js/countera-admin-script.js
Version Parameters
countera/inc/admin/css/countera-admin-style.css?ver=countera/inc/admin/js/countera-admin-script.js?ver=

HTML / DOM Fingerprints

CSS Classes
countera-admin-style
FAQ

Frequently Asked Questions about Countera