
MWR Hit Counter Security & Risk Analysis
wordpress.org/plugins/mwr-hit-counterMWR Hit Counter is a simple and lightweight text-based counter for your website.
Is MWR Hit Counter Safe to Use in 2026?
Generally Safe
Score 100/100MWR Hit Counter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The mwr-hit-counter plugin v1.1.0 presents a generally good security posture with several positive indicators. The static analysis reveals no direct vulnerabilities in terms of dangerous functions, file operations, or external HTTP requests. Crucially, all identified output is properly escaped, and there are no critical or high-severity taint flows detected. The plugin also has no recorded vulnerability history, which suggests a history of secure development practices.
However, there are significant areas of concern that introduce risk. The plugin's handling of SQL queries is a major red flag, with all three queries being executed without the use of prepared statements. This leaves the plugin susceptible to SQL injection vulnerabilities. Furthermore, the absence of nonce checks and capability checks, especially given the presence of a shortcode which is an entry point, indicates a lack of robust authentication and authorization mechanisms. While the attack surface is currently small and appears to have no unprotected entry points based on the provided data, the lack of these fundamental security controls means that if any new entry points are introduced or existing ones are modified, they could easily become vulnerable.
In conclusion, while mwr-hit-counter v1.1.0 benefits from a clean vulnerability history and proper output escaping, the unaddressed risks associated with raw SQL queries and the absence of nonces and capability checks are serious oversights. These issues significantly increase the plugin's vulnerability to common web attacks, despite the current lack of reported CVEs.
Key Concerns
- Raw SQL queries without prepared statements
- Missing nonce checks
- Missing capability checks
MWR Hit Counter Security Vulnerabilities
MWR Hit Counter Code Analysis
SQL Query Safety
Output Escaping
MWR Hit Counter Attack Surface
Shortcodes 1
WordPress Hooks 1
Maintenance & Trust
MWR Hit Counter Maintenance & Trust
Maintenance Signals
Community Trust
MWR Hit Counter Alternatives
Page View Count
page-views-count
Places an icon, all time views count and views today count at the bottom of posts, pages and custom post types on any WordPress website.
MCB – Stats
mcb-stats
MCB Stats collects statistics of users who access to the front part of wordpress, MCB Stast is capable of collecting the total amount of time a user s …
Simple Page Views with Analytics
simple-page-views-with-analytics
Track page views, devices, browsers, and countries with this lightweight plugin. Display data using a simple shortcode anywhere on your site.
WPS Visitor Counter
wps-visitor-counter
Display website visitor statistics with widget, shortcode, and Gutenberg block support.
Page Visits Counter – Lite
page-visits-counter-lite
Display number of visits for each page in admin dashboard and browser developer-tool/console. Doesn't count page refresh as a new visit...
MWR Hit Counter Developer Profile
1 plugin · 100 total installs
How We Detect MWR Hit Counter
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
mwrcounter