
Multi Counter Security & Risk Analysis
wordpress.org/plugins/multi-counterThis plugin allows you to add four counters on the site: Google Analytics, Yandex Metrics, StatCounter, Openstat!
Is Multi Counter Safe to Use in 2026?
Generally Safe
Score 85/100Multi Counter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "multi-counter" v1.2.1 presents a significant security risk primarily due to its unprotected AJAX handlers. All five identified AJAX entry points lack proper authentication checks, meaning any authenticated user could potentially trigger these functions, leading to unauthorized actions or data manipulation. While the plugin avoids dangerous functions and uses prepared statements for its SQL queries, this strength is overshadowed by the critical weakness of unescaped output across all identified outputs (24 total). This lack of output sanitization creates a high probability of Cross-Site Scripting (XSS) vulnerabilities, where malicious scripts could be injected and executed in the context of a user's browser session.
The vulnerability history shows no recorded CVEs, which might initially suggest a good security track record. However, given the critical findings in the static analysis, this history might be misleading. It could indicate that the plugin hasn't been thoroughly audited or that previous vulnerabilities were not publicly disclosed. The absence of taint analysis data is also a concern, as it means potential data flow vulnerabilities might have been missed.
In conclusion, "multi-counter" v1.2.1 exhibits poor security practices, particularly regarding input validation and output sanitization for its AJAX endpoints. The lack of authentication on all AJAX handlers and the universal failure to escape output are major security concerns. While the use of prepared SQL statements is a positive, it does not mitigate the severe risks of XSS and unauthorized AJAX execution. This plugin should be treated with extreme caution until these critical vulnerabilities are addressed.
Key Concerns
- AJAX handlers without authentication checks
- All outputs unescaped (XSS risk)
- No nonce checks on AJAX handlers
- No capability checks on AJAX handlers
Multi Counter Security Vulnerabilities
Multi Counter Code Analysis
Output Escaping
Multi Counter Attack Surface
AJAX Handlers 5
WordPress Hooks 2
Maintenance & Trust
Multi Counter Maintenance & Trust
Maintenance Signals
Community Trust
Multi Counter Alternatives
DCO Insert Analytics Code
dco-insert-analytics-code
Allows you to insert analytics code before </head> or after <body> or before </body>
Komito Analytics
komito-analytics
Komito Analytics is a free, open-source enhancement for the most popular web analytics software.
StatCounter Popular Posts
statcounter-popular-posts
Displays Popular Posts From StatCounter stats as a widget. Only you have to do is make the stats public and give the project ID to this plugin.
Zamango Analytics
zamango-analytics
Plugin to add Google Analytics tracker, GoStats tracker or different web tracker to each page on your weblog without making any changes to your templa …
MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy)
google-analytics-for-wordpress
The best free Google Analytics plugin for WordPress. See how visitors find and use your website so you can grow your business with powerful analytics.
Multi Counter Developer Profile
4 plugins · 50 total installs
How We Detect Multi Counter
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/multi-counter/assets/css/mx-widget-style.css/wp-content/plugins/multi-counter/assets/js/mx-widget-script.js/wp-content/plugins/multi-counter/assets/js/mx-config.js/wp-content/plugins/multi-counter/assets/js/mx-widget-script.js/wp-content/plugins/multi-counter/assets/js/mx-config.jsHTML / DOM Fingerprints
mx-widgetdata-widget-url/wp-json/mx-analytics