Jellyfish Counter Widget Security & Risk Analysis

wordpress.org/plugins/jellyfish-counter-widget

Show eye catching totals with static or animated counter widgets and shortcodes. Classic retro odometer style or easy customise your own custom look.

1K active installs v1.4.4 PHP + WP 3.0+ Updated Apr 2, 2020
animatedcountermilometerodometerwidget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Jellyfish Counter Widget Safe to Use in 2026?

Generally Safe

Score 85/100

Jellyfish Counter Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The "jellyfish-counter-widget" plugin, in version 1.4.4, exhibits a generally strong security posture based on the provided static analysis. The absence of direct SQL queries, file operations, and external HTTP requests, along with a lack of known vulnerabilities, are positive indicators. The attack surface is also minimal, with only one shortcode identified and no unprotected entry points. However, a significant concern arises from the low percentage of properly escaped output (29%). This suggests that user-supplied data might not be adequately sanitized before being displayed, potentially leading to cross-site scripting (XSS) vulnerabilities, especially if the shortcode processes user input.

Key Concerns

  • Low output escaping rate
Vulnerabilities
None known

Jellyfish Counter Widget Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Jellyfish Counter Widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
84
35 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

29% escaped119 total outputs
Attack Surface

Jellyfish Counter Widget Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[jellyfish_counter] jellyfish-counter-widget.php:46
WordPress Hooks 2
actioninitjellyfish-counter-widget.php:30
actionwidgets_initjellyfish-counter-widget.php:31
Maintenance & Trust

Jellyfish Counter Widget Maintenance & Trust

Maintenance Signals

WordPress version tested5.4.19
Last updatedApr 2, 2020
PHP min version
Downloads62K

Community Trust

Rating88/100
Number of ratings10
Active installs1K
Developer Profile

Jellyfish Counter Widget Developer Profile

Strawberry Jellyfish

3 plugins · 1K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Jellyfish Counter Widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/jellyfish-counter-widget/jellyfish-odometer-class/css/jellyfish-counter.css/wp-content/plugins/jellyfish-counter-widget/jellyfish-odometer-class/js/jellyfish-odometer.js/wp-content/plugins/jellyfish-counter-widget/js/jellyfish-counter-loader.js
Script Paths
jellyfish-odometer-class/js/jellyfish-odometer.jsjs/jellyfish-counter-loader.js
Version Parameters
jellyfish-odometer-class/css/jellyfish-counter.css?ver=jellyfish-odometer-class/js/jellyfish-odometer.js?ver=js/jellyfish-counter-loader.js?ver=

HTML / DOM Fingerprints

CSS Classes
jellyfish-counter
Data Attributes
data-digitsdata-formatdata-tenthsdata-digit-heightdata-digit-widthdata-digit-padding+14 more
Shortcode Output
<div class="jellyfish-counter"
FAQ

Frequently Asked Questions about Jellyfish Counter Widget