Post Word Counter – Content Insights Dashboard Security & Risk Analysis

wordpress.org/plugins/doubledome-wordcount-details-dashboard

The Word Counter plugin offers a dedicated dashboard view that tracks the word count, post count, pages wordcount, and custom post types across your e …

200 active installs v2.1 PHP + WP 5.4+ Updated Dec 9, 2025
page-statistics-dashboardpost-count-displayword-countwordcountwordpress-content-analytics
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Post Word Counter – Content Insights Dashboard Safe to Use in 2026?

Generally Safe

Score 100/100

Post Word Counter – Content Insights Dashboard has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The "doubledome-wordcount-details-dashboard" v2.1 plugin exhibits a mixed security posture. On the positive side, the absence of known vulnerabilities in its history and the secure handling of SQL queries via prepared statements are commendable. The plugin also shows a good effort in output escaping, with a high percentage of outputs being properly sanitized, and no detected file operations or external HTTP requests. This suggests a development team that is generally aware of security best practices.

However, the static analysis reveals a significant concern: a single AJAX handler that lacks any authentication checks. This represents an unprotected entry point into the plugin's functionality, creating a potential attack vector. While there are no reported critical taint flows or dangerous function uses, the presence of an unauthenticated AJAX endpoint is a critical oversight that could be exploited by attackers to trigger unintended actions or reveal sensitive information, depending on what the AJAX handler performs.

In conclusion, while the plugin demonstrates good practices in several areas, the unprotected AJAX handler significantly elevates the risk. The clean vulnerability history is a positive sign, but it doesn't negate the immediate risk posed by the identified unprotected entry point. Developers should prioritize implementing proper authentication and authorization checks for this AJAX handler to mitigate the identified security weakness.

Key Concerns

  • Unprotected AJAX handler
  • Missing nonce checks on AJAX
  • Low percentage of properly escaped outputs
Vulnerabilities
None known

Post Word Counter – Content Insights Dashboard Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Post Word Counter – Content Insights Dashboard Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
15 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

83% escaped18 total outputs
Attack Surface
1 unprotected

Post Word Counter – Content Insights Dashboard Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_wc_dd_export_statsincludes\exporter.php:22
WordPress Hooks 11
actionplugins_loadeddoubledome-word-count.php:22
filtermanage_posts_columnsincludes\admin-columns.php:2
filtermanage_pages_columnsincludes\admin-columns.php:3
actionmanage_posts_custom_columnincludes\admin-columns.php:10
actionmanage_pages_custom_columnincludes\admin-columns.php:11
actionadmin_post_dd_export_statsincludes\exporter.php:2
actionadmin_initincludes\settings-page.php:3
actionadmin_menuincludes\settings-page.php:7
actionwp_dashboard_setupincludes\wcfunctions.php:6
actionadmin_enqueue_scriptsincludes\wcfunctions.php:177
actionadd_meta_boxesincludes\wcfunctions.php:197
Maintenance & Trust

Post Word Counter – Content Insights Dashboard Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 9, 2025
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs200
Developer Profile

Post Word Counter – Content Insights Dashboard Developer Profile

doubledome

6 plugins · 620 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
26 days
View full developer profile
Detection Fingerprints

How We Detect Post Word Counter – Content Insights Dashboard

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/doubledome-wordcount-details-dashboard/css/styles.css/wp-content/plugins/doubledome-wordcount-details-dashboard/js/counter.js/wp-content/plugins/doubledome-wordcount-details-dashboard/js/settings.js
Script Paths
/wp-content/plugins/doubledome-wordcount-details-dashboard/js/settings.js/wp-content/plugins/doubledome-wordcount-details-dashboard/js/counter.js
Version Parameters
doubledome-wordcount-details-dashboard/js/counter.js?ver=2.0

HTML / DOM Fingerprints

CSS Classes
wc_dd_dashboard_widget
JS Globals
ddWordCounterSettings
FAQ

Frequently Asked Questions about Post Word Counter – Content Insights Dashboard