
IDClass Click Counter Security & Risk Analysis
wordpress.org/plugins/idclass-click-counterShort Description: A plugin to track user clicks on specific HTML elements using unique IDs or classes.
Is IDClass Click Counter Safe to Use in 2026?
Generally Safe
Score 92/100IDClass Click Counter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'idclass-click-counter' plugin, version 1.0, exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, SQL injection vulnerabilities, file operations, and external HTTP requests is highly commendable. The plugin also demonstrates good practices by using prepared statements for all SQL queries and properly escaping the vast majority of its output, with only one minor output escaping concern identified. Furthermore, the presence of nonce checks on its entry points is a positive indicator of security awareness. The plugin's vulnerability history is clean, with no recorded CVEs, suggesting a history of secure development or a lack of past targeted attacks. However, the primary area of concern lies in the complete absence of capability checks for its AJAX handlers. While the attack surface is small and there are no unauthenticated entry points, the lack of role-based access control for these handlers means that any authenticated user, regardless of their permissions, could potentially trigger these AJAX actions. This could lead to unintended consequences or be leveraged in conjunction with other, hypothetical vulnerabilities. Overall, this plugin appears to be developed with security in mind, but the missing capability checks on AJAX handlers represent a tangible risk that should be addressed.
Key Concerns
- Missing capability checks on AJAX handlers
- Minor unescaped output detected
IDClass Click Counter Security Vulnerabilities
IDClass Click Counter Code Analysis
Output Escaping
Data Flow Analysis
IDClass Click Counter Attack Surface
AJAX Handlers 2
WordPress Hooks 6
Maintenance & Trust
IDClass Click Counter Maintenance & Trust
Maintenance Signals
Community Trust
IDClass Click Counter Alternatives
GA Google Analytics – Connect Google Analytics to WordPress
ga-google-analytics
Adds Google Analytics tracking code to your WordPress site. Supports many tracking features.
Metricool
metricool
Metricool is the first tool designed to measure #Blog impact and #SocialMedia activity.
SlimStat Analytics
wp-slimstat
The leading web analytics plugin for WordPress
Connect Matomo – Analytics Dashboard for WordPress
wp-piwik
Adds Matomo (former Piwik) statistics to your WordPress dashboard and is also able to add the Matomo Tracking Code to your blog.
Pixel Manager for WooCommerce – Conversion Tracking, Google Ads, GA4, TikTok, Dynamic Remarketing
woocommerce-google-adwords-conversion-tracking-tag
Conversion tracking for WooCommerce. Google Ads, GA4, Meta/Facebook Pixel, TikTok & more. Recover 30% more conversions with server-side tracking!
IDClass Click Counter Developer Profile
2 plugins · 40 total installs
How We Detect IDClass Click Counter
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/idclass-click-counter/assets/css/click-counter.css/wp-content/plugins/idclass-click-counter/assets/js/click-counter.js/wp-content/plugins/idclass-click-counter/assets/js/click-counter.jsidclass-click-counter/assets/css/click-counter.css?ver=idclass-click-counter/assets/js/click-counter.js?ver=HTML / DOM Fingerprints
click-counter-settingsclick-counter-listelement-nameclick-countbutton-groupdelete-buttonadd-element-formdata-elementclickCounterAjax