GA-PVcounter Security & Risk Analysis

wordpress.org/plugins/ga-pvcounter

Google Analytics PageView counter and Popular posts, Recent posts widget

10 active installs v0.4.0 PHP + WP 3.4+ Updated Oct 1, 2013
counterpage-viewpopular-postsrecent-postswidget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is GA-PVcounter Safe to Use in 2026?

Generally Safe

Score 85/100

GA-PVcounter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12yr ago
Risk Assessment

The "ga-pvcounter" v0.4.0 plugin presents a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for its SQL queries and has no known vulnerabilities or CVEs in its history, suggesting a generally stable and well-maintained codebase. The plugin also has a relatively small attack surface with only one shortcode as an entry point and no AJAX handlers or REST API routes exposed without permission checks.

Key Concerns

  • Dangerous functions found (unserialize)
  • Insufficient output escaping (19% proper)
  • No nonce checks found
  • Limited capability checks (1)
Vulnerabilities
None known

GA-PVcounter Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

GA-PVcounter Code Analysis

Dangerous Functions
2
Raw SQL Queries
0
0 prepared
Unescaped Output
56
13 escaped
Nonce Checks
0
Capability Checks
1
File Operations
7
External Requests
2
Bundled Libraries
0

Dangerous Functions Found

unserializereturn unserialize($ret['data']);google-api-php-client\src\cache\Google_ApcCache.php:79
unserialize$data = unserialize($data);google-api-php-client\src\cache\Google_FileCache.php:100

Output Escaping

19% escaped69 total outputs
Attack Surface

GA-PVcounter Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[GA_PVC] GA-PVcounter.php:152
WordPress Hooks 4
actionwidgets_initGA-PVcounter.php:151
filterwidget_textGA-PVcounter.php:155
actionadmin_menuGA-PVcounter.php:159
actionadmin_initGA-PVcounter.php:160
Maintenance & Trust

GA-PVcounter Maintenance & Trust

Maintenance Signals

WordPress version tested3.6.1
Last updatedOct 1, 2013
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

GA-PVcounter Developer Profile

enomoto celtislab

12 plugins · 9K total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect GA-PVcounter

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ga-pvcounter/ga-pvcounter-style.css/wp-content/plugins/ga-pvcounter/google-api-php-client/src/Google_Client.php/wp-content/plugins/ga-pvcounter/google-api-php-client/src/contrib/Google_AnalyticsService.php/wp-content/plugins/ga-pvcounter/js/ga-pvcounter.js
Version Parameters
ga-pvcounter/ga-pvcounter-style.css?ver=ga-pvcounter/js/ga-pvcounter.js?ver=

HTML / DOM Fingerprints

CSS Classes
ga-pvcounter-popularga-pvcounter-recent
Shortcode Output
[GA_PVC]
FAQ

Frequently Asked Questions about GA-PVcounter