
MC Annual Upcounter Security & Risk Analysis
wordpress.org/plugins/mc-annual-upcounterPounds of wasted food, gallons of ice cream, babies born, cars sold ... any number that accrues througout the year, updated live on the website page.
Is MC Annual Upcounter Safe to Use in 2026?
Generally Safe
Score 100/100MC Annual Upcounter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "mc-annual-upcounter" v2.1.2 plugin exhibits a generally strong security posture with no known vulnerabilities or CVEs recorded, which is a significant positive indicator. The static analysis reveals a minimal attack surface, with only one shortcode and no AJAX handlers or REST API routes exposed without authentication. Furthermore, the code demonstrates good practices by using prepared statements for all SQL queries and performing no file operations or external HTTP requests. However, a notable concern is the low percentage of properly escaped output, with only one-third of identified outputs being sanitized. This could potentially lead to cross-site scripting (XSS) vulnerabilities if user-controlled data is present in the unescaped outputs. The absence of any identified taint flows is a positive sign, suggesting that sensitive data is not being mishandled. Overall, while the plugin avoids common pitfalls like raw SQL or unauthenticated entry points, the unescaped output represents a tangible risk that needs attention. The lack of vulnerability history is encouraging but doesn't negate the findings from the static analysis.
Key Concerns
- Low output escaping percentage
MC Annual Upcounter Security Vulnerabilities
MC Annual Upcounter Release Timeline
MC Annual Upcounter Code Analysis
Output Escaping
MC Annual Upcounter Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
MC Annual Upcounter Maintenance & Trust
Maintenance Signals
Community Trust
MC Annual Upcounter Alternatives
MC Annual Upcounter Developer Profile
6 plugins · 240 total installs
How We Detect MC Annual Upcounter
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mc-annual-upcounter/assets/MC-AU-Head.jpgHTML / DOM Fingerprints
id="mc6397au_Counter"incrementfrequency<span id='mc6397au_Counter'>Calculating ...</span>