
Image Counter Security & Risk Analysis
wordpress.org/plugins/image-counterThis plugin adds a small counter to each image in your posts.
Is Image Counter Safe to Use in 2026?
Generally Safe
Score 85/100Image Counter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "image-counter" plugin v0.4.1 exhibits a strong initial security posture, with no recorded vulnerabilities in its history and a clean static analysis report regarding dangerous functions, SQL queries, file operations, and external HTTP requests. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface, and the limited code signals indicate careful development. However, a critical concern arises from the output escaping: 100% of the five identified output points are not properly escaped. This indicates a potential for Cross-Site Scripting (XSS) vulnerabilities, where malicious scripts could be injected and executed within the WordPress admin or frontend if user-supplied data is not sanitized before being displayed.
The plugin's vulnerability history is a significant strength, showing no known CVEs. This suggests a track record of secure development or a lack of targeted attacks. The sole capability check is a positive sign, indicating an attempt to enforce access control. Despite the lack of identified taint flows or critical security issues in the static analysis, the unescaped output is a serious oversight that could lead to exploitable vulnerabilities. Therefore, while the plugin has a good foundation, the lack of output escaping presents a notable risk.
Key Concerns
- All identified outputs are unescaped
Image Counter Security Vulnerabilities
Image Counter Code Analysis
Output Escaping
Data Flow Analysis
Image Counter Attack Surface
WordPress Hooks 3
Maintenance & Trust
Image Counter Maintenance & Trust
Maintenance Signals
Community Trust
Image Counter Alternatives
Image Overlay Cues
image-overlay-cues
Image Overlay Cues is a WordPress plugin designed to enhance the core image block with an additional overlay count feature.
Instant Images – One-click Image Uploads from Unsplash, Openverse, Pixabay, Pexels, and Giphy
instant-images
One-click uploads from Unsplash, Openverse, Pixabay, Pexels, and Giphy directly to your WordPress media library.
FancyBox for WordPress
fancybox-for-wordpress
Seamlessly integrates FancyBox lightbox into your WordPress blog: Upload, activate, and you're done. Additional configuration optional.
Lightbox with PhotoSwipe
lightbox-photoswipe
Integration of PhotoSwipe (http://photoswipe.com) for WordPress.
Weblizar Pin It Button On Image Hover And Post
pinterest-pin-it-button-on-image-hover-and-post
Pin Your Images With weblizar pin it button on image hover and post.
Image Counter Developer Profile
5 plugins · 150 total installs
How We Detect Image Counter
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/image-counter/style.cssHTML / DOM Fingerprints
imageimage-countdata-image-counter-options