FX HEY counter Security & Risk Analysis

wordpress.org/plugins/fx-hey-counter

Plugin displays visitors counter from www.hey.lt site. No need to insert code, jus simply activate plugin, set ID and you will have widget.

10 active installs v1.0.3 PHP + WP 2.8+ Updated May 20, 2011
countervisitors
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is FX HEY counter Safe to Use in 2026?

Generally Safe

Score 85/100

FX HEY counter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 14yr ago
Risk Assessment

The fx-hey-counter v1.0.3 plugin exhibits a strong security posture based on the provided static analysis. It has no reported vulnerabilities, a minimal attack surface with no apparent entry points, and avoids dangerous functions. The use of prepared statements for all SQL queries is a significant strength, indicating good practices in database interaction. However, a notable concern is the complete lack of output escaping. With 2 outputs identified and 0% properly escaped, this presents a significant risk of Cross-Site Scripting (XSS) vulnerabilities. Attackers could potentially inject malicious scripts through the plugin's output, which could then be executed in the browser of other users. The absence of vulnerability history further suggests that the plugin has historically been secure, but this cannot entirely mitigate the identified output escaping issue. The plugin's strengths lie in its limited attack surface and secure database handling, but the critical weakness in output sanitization requires immediate attention to prevent XSS attacks.

Key Concerns

  • 0% output escaping
Vulnerabilities
None known

FX HEY counter Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

FX HEY counter Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped2 total outputs
Attack Surface

FX HEY counter Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionwidgets_initfx-hey-counter.php:82
Maintenance & Trust

FX HEY counter Maintenance & Trust

Maintenance Signals

WordPress version tested3.0.5
Last updatedMay 20, 2011
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

FX HEY counter Developer Profile

AivarasFX

3 plugins · 30 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect FX HEY counter

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about FX HEY counter