
Liz Comment Counter by Ozh Security & Risk Analysis
wordpress.org/plugins/liz-comment-counter-by-ozhA highly configurable badge to show off the number of comments your blog has.
Is Liz Comment Counter by Ozh Safe to Use in 2026?
Generally Safe
Score 100/100Liz Comment Counter by Ozh has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The liz-comment-counter-by-ozh plugin, v1.1.3, presents a generally good security posture due to a notably small attack surface and a clean vulnerability history. The absence of any registered CVEs, along with no reported common vulnerability types, suggests a history of stable and secure development. The static analysis also reveals no critical or high-severity taint flows, indicating that user-supplied data is not being directly manipulated in ways that could lead to serious exploits.
However, there are areas of concern. The plugin utilizes one instance of the `preg_replace(/e)` function, which is known to be a potential vulnerability if not handled with extreme care, as it can lead to code execution. Additionally, the plugin performs a SQL query without using prepared statements, which is a common vector for SQL injection attacks, especially if the query involves user-supplied data. The low percentage of properly escaped output (16%) is also a significant weakness, increasing the risk of cross-site scripting (XSS) vulnerabilities, particularly if any of the data displayed originates from user input or external sources.
In conclusion, while the plugin's attack surface and CVE history are positive indicators, the presence of a potentially dangerous function, unescaped output, and raw SQL queries introduce significant risks that should be addressed. The absence of capability checks on its entry points is also a concern, though the lack of entry points limits this immediate risk. A thorough review of the `preg_replace` usage and all SQL queries, along with comprehensive output escaping, is highly recommended.
Key Concerns
- Dangerous function: preg_replace(/e)
- SQL queries without prepared statements
- Low percentage of properly escaped output
- No capability checks on entry points
Liz Comment Counter by Ozh Security Vulnerabilities
Liz Comment Counter by Ozh Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Liz Comment Counter by Ozh Attack Surface
WordPress Hooks 7
Maintenance & Trust
Liz Comment Counter by Ozh Maintenance & Trust
Maintenance Signals
Community Trust
Liz Comment Counter by Ozh Alternatives
Remove noreferrer
remove-noreferrer
"Remove noreferrer" automatically removes rel="noreferrer" attribute from links on your website on-the-fly.
Better Recent Comments
better-recent-comments
Provides an improved Recent Comments widget and a shortcode to display your recent comments on any post or page.
Recent Comments Widget Plus
comments-widget-plus
Provides custom recent comments widget with extra features such as display avatar, comment excerpt and much more!
Better WordPress Recent Comments
bwp-recent-comments
This plugin displays recent comment lists at assigned locations, with comprehensive support for widgets.
GraphComment Comment system
graphcomment-comment-system
Transform your site's engagement with GraphComment—an advanced, interactive commenting system featuring live discussions and real-time notifications.
Liz Comment Counter by Ozh Developer Profile
27 plugins · 5K total installs
How We Detect Liz Comment Counter by Ozh
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/liz-comment-counter-by-ozh/css/style.cssliz-comment-counter-by-ozh/css/style.css?ver=