Counting Number Block Security & Risk Analysis

wordpress.org/plugins/counting-number-block

This block provides an animated counter effect for numbers. It’s fast, lightweight, SEO-friendly, accessibility-ready, and fits any design.

1K active installs v1.1.2 PHP 7.0+ WP 5.9+ Updated Feb 11, 2026
animationblockcountergutenbergnumber
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Counting Number Block Safe to Use in 2026?

Generally Safe

Score 100/100

Counting Number Block has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

Based on the static analysis and vulnerability history provided, the 'counting-number-block' plugin v1.1.2 exhibits a strong security posture. The code analysis reveals no dangerous functions, no raw SQL queries, and all output is properly escaped. Crucially, there are no identified flows from taint analysis, indicating no vulnerabilities related to user-supplied data being mishandled. The plugin also demonstrates a lack of file operations and external HTTP requests, further reducing its attack surface. The absence of known CVEs and a clean vulnerability history further solidify its current security standing.

However, it's important to note the complete absence of nonce and capability checks across all entry points, including AJAX handlers and REST API routes. While the current analysis shows zero unprotected entry points, this lack of explicit authentication and authorization mechanisms represents a significant potential weakness. Should any new entry points be introduced or existing ones become exposed through future updates or plugin interactions, the absence of these fundamental security checks could lead to vulnerabilities. The plugin's strengths lie in its clean code and lack of known historical issues, but its reliance on an implicit security model for its entry points is a notable concern for ongoing security.

Key Concerns

  • Missing nonce checks on entry points
  • Missing capability checks on entry points
Vulnerabilities
None known

Counting Number Block Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Counting Number Block Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Counting Number Block Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actioninitcounting-number.php:30
Maintenance & Trust

Counting Number Block Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 11, 2026
PHP min version7.0
Downloads13K

Community Trust

Rating100/100
Number of ratings9
Active installs1K
Developer Profile

Counting Number Block Developer Profile

Phi Phan

8 plugins · 27K total installs

100
trust score
Avg Security Score
100/100
Avg Patch Time
6 days
View full developer profile
Detection Fingerprints

How We Detect Counting Number Block

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/counting-number-block/build/index.js/wp-content/plugins/counting-number-block/build/style-index.css
Script Paths
/wp-content/plugins/counting-number-block/build/index.js
Version Parameters
/wp-content/plugins/counting-number-block/build/index.js?ver=/wp-content/plugins/counting-number-block/build/style-index.css?ver=

HTML / DOM Fingerprints

CSS Classes
wp-block-counting-number-block
Data Attributes
data-start-numdata-end-numdata-durationdata-delay
FAQ

Frequently Asked Questions about Counting Number Block