Liz Comment Counter by Ozh Security & Risk Analysis

wordpress.org/plugins/liz-comment-counter-by-ozh

A highly configurable badge to show off the number of comments your blog has.

10 active installs v1.1.3 PHP + WP 2.8+ Updated Unknown
badgecommentcommentsozhwidget
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Liz Comment Counter by Ozh Safe to Use in 2026?

Generally Safe

Score 100/100

Liz Comment Counter by Ozh has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The liz-comment-counter-by-ozh plugin, v1.1.3, presents a generally good security posture due to a notably small attack surface and a clean vulnerability history. The absence of any registered CVEs, along with no reported common vulnerability types, suggests a history of stable and secure development. The static analysis also reveals no critical or high-severity taint flows, indicating that user-supplied data is not being directly manipulated in ways that could lead to serious exploits.

However, there are areas of concern. The plugin utilizes one instance of the `preg_replace(/e)` function, which is known to be a potential vulnerability if not handled with extreme care, as it can lead to code execution. Additionally, the plugin performs a SQL query without using prepared statements, which is a common vector for SQL injection attacks, especially if the query involves user-supplied data. The low percentage of properly escaped output (16%) is also a significant weakness, increasing the risk of cross-site scripting (XSS) vulnerabilities, particularly if any of the data displayed originates from user input or external sources.

In conclusion, while the plugin's attack surface and CVE history are positive indicators, the presence of a potentially dangerous function, unescaped output, and raw SQL queries introduce significant risks that should be addressed. The absence of capability checks on its entry points is also a concern, though the lack of entry points limits this immediate risk. A thorough review of the `preg_replace` usage and all SQL queries, along with comprehensive output escaping, is highly recommended.

Key Concerns

  • Dangerous function: preg_replace(/e)
  • SQL queries without prepared statements
  • Low percentage of properly escaped output
  • No capability checks on entry points
Vulnerabilities
None known

Liz Comment Counter by Ozh Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Liz Comment Counter by Ozh Code Analysis

Dangerous Functions
1
Raw SQL Queries
1
0 prepared
Unescaped Output
42
8 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

preg_replace(/e)preg_replace('/, ([^,]*?)$/e'inc\core.php:108

SQL Query Safety

0% prepared1 total queries

Output Escaping

16% escaped50 total outputs
Attack Surface

Liz Comment Counter by Ozh Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionin_admin_footerinc\optionpage.php:19
actionwidgets_initwp_ozh_lcc.php:43
actionadmin_menuwp_ozh_lcc.php:44
filterozh_adminmenu_icon_ozh_lccwp_ozh_lcc.php:47
actionplugins_loadedwp_ozh_lcc.php:103
actioncomment_postwp_ozh_lcc.php:104
actionwp_set_comment_statuswp_ozh_lcc.php:105
Maintenance & Trust

Liz Comment Counter by Ozh Maintenance & Trust

Maintenance Signals

WordPress version tested9.9
Last updatedUnknown
PHP min version
Downloads8K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Liz Comment Counter by Ozh Developer Profile

Ozh

27 plugins · 5K total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Liz Comment Counter by Ozh

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/liz-comment-counter-by-ozh/css/style.css
Version Parameters
liz-comment-counter-by-ozh/css/style.css?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Liz Comment Counter by Ozh