
My Contador lesr Security & Risk Analysis
wordpress.org/plugins/my-contador-wp¡Gracias por descargar nuestro plugin! Con más de 5000 descargas, estamos emocionados de ver cómo ha ayudado a nuestros
Is My Contador lesr Safe to Use in 2026?
Generally Safe
Score 91/100My Contador lesr has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The plugin "my-contador-wp" v2.0 exhibits a mixed security posture. On the positive side, the static analysis reveals a small attack surface with only one shortcode identified as an entry point. Furthermore, the absence of detected critical or high severity taint flows and dangerous functions suggests some level of secure coding practices. The plugin also demonstrates some awareness of security by including capability checks and a limited number of SQL queries. However, there are notable areas for concern.
The primary weakness lies in the output escaping and the SQL query handling. With only 25% of outputs properly escaped and 36% of SQL queries using prepared statements, there's a significant risk of cross-site scripting (XSS) vulnerabilities and SQL injection flaws. The lack of nonce checks, while not directly tied to an unprotected entry point in this analysis, is a general security oversight that could be exploited if other vulnerabilities are present or introduced.
The vulnerability history, specifically a medium severity CVE related to "Missing Authorization" that was recently patched, indicates a past security weakness. While it's currently unpatched, this pattern suggests a recurring need for thorough code reviews and security testing, particularly around authorization logic, to prevent future exploitable vulnerabilities.
Key Concerns
- Low percentage of properly escaped output
- Low percentage of SQL queries using prepared statements
- Missing nonce checks
- Medium severity CVE history (Missing Authorization)
My Contador lesr Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
My Contador lesr <= 2.0 - Missing Authorization to Unauthenticated User Registration CSV Export
My Contador lesr Release Timeline
My Contador lesr Code Analysis
SQL Query Safety
Output Escaping
My Contador lesr Attack Surface
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
My Contador lesr Maintenance & Trust
Maintenance Signals
Community Trust
My Contador lesr Alternatives
Shortcoder — Create Shortcodes for Anything
shortcoder
Create custom "Shortcodes" easily for HTML, JavaScript, CSS code snippets and use the shortcodes within posts, pages & widgets
Post Snippets – Custom WordPress Code Snippets Customizer
post-snippets
Create WordPress custom snippets shortcodes and reusable content and insert them in into your posts and pages.
WP Coder – Insert & Manage Code Snippets
wp-coder
Snippets made simple — easily insert and manage custom PHP, CSS, JS & HTML without coding in theme files.
Snippet Shortcodes
shortcode-variables
Create a library of custom shortcodes and reusable content, and seamlessly insert them into your posts and pages.
Slideshow
slideshow
A shortcode for displaying a slideshow of image attachments for a post.
My Contador lesr Developer Profile
1 plugin · 100 total installs
How We Detect My Contador lesr
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/my-contador-wp/js/contador.js/wp-content/plugins/my-contador-wp/css/contador.css/wp-content/plugins/my-contador-wp/js/contador.jsHTML / DOM Fingerprints
Su código de transacción es: <span id='codigoG'>Si ya ha terminado su transacción, por favor espere