
Counters Block – Animated Number Counters for Stats and Goals Security & Risk Analysis
wordpress.org/plugins/counters-blockA great way to display numbers in a fun and interesting way.
Is Counters Block – Animated Number Counters for Stats and Goals Safe to Use in 2026?
Generally Safe
Score 99/100Counters Block – Animated Number Counters for Stats and Goals has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The 'counters-block' plugin version 2.0.5 exhibits a generally strong security posture based on the provided static analysis. All identified entry points, including a shortcode, are either absent or protected by capability checks, indicating good access control practices. The complete absence of dangerous functions, file operations, and external HTTP requests, coupled with the use of prepared statements for all SQL queries and proper output escaping, are significant strengths that mitigate common web application vulnerabilities. The taint analysis showing zero flows with unsanitized paths further bolsters this positive assessment.
However, the vulnerability history reveals a past medium-severity Cross-Site Scripting (XSS) vulnerability, even though it is currently patched. The fact that an XSS vulnerability was present suggests potential weaknesses in input sanitization or output encoding that might not be fully captured by the current static analysis, or that the vulnerability was in a previous version. The lack of nonce checks on the single shortcode entry point is a minor concern, as it could potentially be exploited in specific scenarios, although the overall attack surface is very small. The inclusion of the Freemius bundled library, while not inherently a security risk, warrants attention if its security posture is not actively managed.
In conclusion, 'counters-block' v2.0.5 appears to be a reasonably secure plugin, with most common vulnerability vectors addressed effectively. The main areas for potential improvement would be to ensure that the historical XSS vulnerability is fully understood and that its root cause has been permanently remediated, and to consider adding nonce checks to the shortcode for an extra layer of protection, even with its limited attack surface. The overall risk is assessed as low.
Key Concerns
- Medium severity XSS vulnerability in history
- Shortcode with potential for CSRF (no nonce checks)
Counters Block – Animated Number Counters for Stats and Goals Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Counters Block <= 1.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
Counters Block – Animated Number Counters for Stats and Goals Release Timeline
Counters Block – Animated Number Counters for Stats and Goals Code Analysis
Bundled Libraries
Output Escaping
Counters Block – Animated Number Counters for Stats and Goals Attack Surface
Shortcodes 1
WordPress Hooks 9
Maintenance & Trust
Counters Block – Animated Number Counters for Stats and Goals Maintenance & Trust
Maintenance Signals
Community Trust
Counters Block – Animated Number Counters for Stats and Goals Alternatives
Block Metrics – Animated State Counter
block-metrics-animated-state-counter
A easy way to display states counter in a easy and interesting way.
Counter Number Showcase, Fun Facts – WordPress Animated Counter Plugin
counter-number-showcase
Counter Number WordPress Plugin brings you all the powerful Stats Counter features to your wordpress website
Animated Number Counters
animated-number-counters
Animated Number Counters is a lightweight, responsive, and mobile-friendly WordPress plugin that boasts extraordinary design.
Counter Block
counter-block
Show off numbers or stats on your website using animated Counter block for Gutenberg.
Number Counter
number-counter
Counter block written with ESNext standard and JSX support – build step required.
Counters Block – Animated Number Counters for Stats and Goals Developer Profile
121 plugins · 740K total installs
How We Detect Counters Block – Animated Number Counters for Stats and Goals
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/counters-block/build/admin-dashboard.asset.php/wp-content/plugins/counters-block/build/admin-post.js/wp-content/plugins/counters-block/build/admin-post.css/wp-content/plugins/counters-block/build/admin-dashboard.js/wp-content/plugins/counters-block/build/admin-dashboard.css/wp-content/plugins/counters-block/public/css/font-awesome.min.css/wp-content/plugins/counters-block/public/js/counters-block.jscounters-block/style.css?ver=counters-block/script.js?ver=HTML / DOM Fingerprints
ctrb-block-wrapctrb-block-headingctrb-block-counterctrb-block-icondata-block-iddata-counter-iddata-counter-valuedata-counter-durationdata-counter-delaydata-counter-easing+3 morewindow.ctrbPrimiumProps/wp-json/counters-block/v1/settings[counters-block