
Jetpack Post Views Security & Risk Analysis
wordpress.org/plugins/jetpack-post-viewsDisplay your most popular posts using Jetpack stats.
Is Jetpack Post Views Safe to Use in 2026?
Generally Safe
Score 85/100Jetpack Post Views has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The jetpack-post-views plugin v1.1.0 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by having no known vulnerabilities, no critical taint flows, and a relatively small attack surface with all identified entry points appearing to have some level of protection (though specific checks are not detailed for all). The absence of file operations and external HTTP requests is also a positive sign.
However, several concerns are raised by the static analysis. The presence of the `unserialize` function twice without context is a significant red flag, as it can lead to remote code execution if used with untrusted input. Furthermore, 100% of the SQL queries are not using prepared statements, which opens the door to SQL injection vulnerabilities. The low percentage of properly escaped output (19%) indicates a high risk of cross-site scripting (XSS) vulnerabilities, especially given the lack of capability checks on entry points.
The plugin's vulnerability history is clean, which is a strength. This suggests that either the plugin has been developed with security in mind, or it hasn't been subjected to extensive targeted attacks. Nonetheless, the inherent risks identified in the static analysis, particularly the use of `unserialize` and raw SQL queries alongside poor output escaping, present significant security weaknesses that outweigh the clean vulnerability history.
Key Concerns
- Dangerous function unserialize used twice
- Raw SQL queries (100% not prepared)
- Low output escaping percentage (19%)
- No capability checks on entry points
Jetpack Post Views Security Vulnerabilities
Jetpack Post Views Release Timeline
Jetpack Post Views Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Jetpack Post Views Attack Surface
Shortcodes 1
WordPress Hooks 11
Scheduled Events 1
Maintenance & Trust
Jetpack Post Views Maintenance & Trust
Maintenance Signals
Community Trust
Jetpack Post Views Alternatives
Post Views for Jetpack
post-views-for-jetpack
Display the number of views for each one of your posts, as recorded by Jetpack Stats.
Jetpack Protect
jetpack-protect
Free daily vulnerability scans & WordPress security, powered by WPScan (an Automattic brand) and its 60,000+ vulnerability database. No setup needed!
Jetpack VaultPress Backup
jetpack-backup
Save each change and get back online fast with one-click restores. The most proven WordPress backup plugin with over 270 million backups.
Page View Count
page-views-count
Places an icon, all time views count and views today count at the bottom of posts, pages and custom post types on any WordPress website.
Tiled Gallery Carousel Without JetPack
tiled-gallery-carousel-without-jetpack
Tiled Gallery with Full Screen Carousel slideshow without Jetpack.
Jetpack Post Views Developer Profile
1 plugin · 200 total installs
How We Detect Jetpack Post Views
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/jetpack-post-views/languages/jetpack-post-views.potHTML / DOM Fingerprints
jetpack-post-viewsCopyright 2013 Steven Lambert (email : steven@sklambert.com)This program is free software; you can redistribute it and/or modifyit under the terms of the GNU General Public License, version 2, aspublished by the Free Software Foundation.+7 morejetpack-post-views_versionjetpack_post_views_settingsjetpack-post-views-widget