Decon Character Counter Security & Risk Analysis

wordpress.org/plugins/decon-character-counter

Counts the title, content, and excerpt characters while you edit your post or page (even in Quick Edit).

30 active installs v0.0.3 PHP + WP 4.2.2+ Updated Sep 22, 2015
charactercountcounterseotitle
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Decon Character Counter Safe to Use in 2026?

Generally Safe

Score 85/100

Decon Character Counter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The security posture of the "decon-character-counter" v0.0.3 plugin appears strong based on the provided static analysis. The absence of any identified dangerous functions, SQL queries executed without prepared statements, and properly escaped output are significant strengths. Furthermore, the lack of file operations, external HTTP requests, and the absence of any known vulnerabilities or CVEs in its history are highly positive indicators. This suggests a well-developed plugin that adheres to secure coding practices.

However, a notable concern is the complete lack of any identified entry points (AJAX handlers, REST API routes, shortcodes, cron events). While this means there are no *currently identified* unprotected entry points, it could also indicate that the plugin's functionality might be extremely limited or that the static analysis tool did not uncover them. A complete absence of entry points without a clear explanation or if the plugin is intended to have user-facing features, is unusual and warrants further investigation to ensure the analysis wasn't incomplete. The lack of any nonce or capability checks, while not directly a risk in the absence of identified entry points, would become a critical vulnerability if any were discovered or if the plugin's functionality were to expand.

Overall, the plugin exhibits excellent code quality and a clean vulnerability history. The primary area for caution is the unusual lack of any attack surface, which could either be a sign of extreme security or potentially an artifact of the analysis. Assuming the analysis is accurate and the plugin's functionality is as limited as indicated, its security is very good. However, the absence of any demonstrable interaction points is an anomaly that should be understood.

Vulnerabilities
None known

Decon Character Counter Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Decon Character Counter Release Timeline

v0.0.3Current
v0.0.2
v0.0.1
Code Analysis
Analyzed Mar 16, 2026

Decon Character Counter Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Decon Character Counter Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionadmin_enqueue_scriptsdecon-character-counter.php:31
Maintenance & Trust

Decon Character Counter Maintenance & Trust

Maintenance Signals

WordPress version tested4.3.34
Last updatedSep 22, 2015
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs30
Developer Profile

Decon Character Counter Developer Profile

Michael Tumlad

1 plugin · 30 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Decon Character Counter

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/decon-character-counter/css/decon-character-counter.css/wp-content/plugins/decon-character-counter/js/decon-character-counter.js
Script Paths
/wp-content/plugins/decon-character-counter/js/decon-character-counter.js
Version Parameters
decon-character-counter.css?ver=decon-character-counter.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Decon Character Counter