My Contador lesr Security & Risk Analysis

wordpress.org/plugins/my-contador-wp

¡Gracias por descargar nuestro plugin! Con más de 5000 descargas, estamos emocionados de ver cómo ha ayudado a nuestros

100 active installs v2.0 PHP + WP 4.5+ Updated Nov 19, 2024
contadorcounteripshortcode
91
A · Safe
CVEs total1
Unpatched0
Last CVENov 20, 2024
Safety Verdict

Is My Contador lesr Safe to Use in 2026?

Generally Safe

Score 91/100

My Contador lesr has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Nov 20, 2024Updated 1yr ago
Risk Assessment

The plugin "my-contador-wp" v2.0 exhibits a mixed security posture. On the positive side, the static analysis reveals a small attack surface with only one shortcode identified as an entry point. Furthermore, the absence of detected critical or high severity taint flows and dangerous functions suggests some level of secure coding practices. The plugin also demonstrates some awareness of security by including capability checks and a limited number of SQL queries. However, there are notable areas for concern.

The primary weakness lies in the output escaping and the SQL query handling. With only 25% of outputs properly escaped and 36% of SQL queries using prepared statements, there's a significant risk of cross-site scripting (XSS) vulnerabilities and SQL injection flaws. The lack of nonce checks, while not directly tied to an unprotected entry point in this analysis, is a general security oversight that could be exploited if other vulnerabilities are present or introduced.

The vulnerability history, specifically a medium severity CVE related to "Missing Authorization" that was recently patched, indicates a past security weakness. While it's currently unpatched, this pattern suggests a recurring need for thorough code reviews and security testing, particularly around authorization logic, to prevent future exploitable vulnerabilities.

Key Concerns

  • Low percentage of properly escaped output
  • Low percentage of SQL queries using prepared statements
  • Missing nonce checks
  • Medium severity CVE history (Missing Authorization)
Vulnerabilities
1 published

My Contador lesr Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-11334medium · 4.3Missing Authorization

My Contador lesr <= 2.0 - Missing Authorization to Unauthenticated User Registration CSV Export

Nov 20, 2024 Patched in 2.1 (1d)
Version History

My Contador lesr Release Timeline

v2.1
v2.0Current1 CVE
v1.11 CVE
v1.01 CVE
Code Analysis
Analyzed Mar 16, 2026

My Contador lesr Code Analysis

Dangerous Functions
0
Raw SQL Queries
7
4 prepared
Unescaped Output
6
2 escaped
Nonce Checks
0
Capability Checks
2
File Operations
1
External Requests
0
Bundled Libraries
0

SQL Query Safety

36% prepared11 total queries

Output Escaping

25% escaped8 total outputs
Attack Surface

My Contador lesr Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[contar] contador.php:89
WordPress Hooks 4
actionadmin_menucontador.php:121
actionadmin_initcontador.php:160
actionactivate_contar/contador.phpcontador.php:348
actiondeactivate_contar/contador.phpcontador.php:350
Maintenance & Trust

My Contador lesr Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedNov 19, 2024
PHP min version
Downloads7K

Community Trust

Rating0/100
Number of ratings0
Active installs100
Developer Profile

My Contador lesr Developer Profile

luydjmi

1 plugin · 100 total installs

94
trust score
Avg Security Score
91/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect My Contador lesr

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/my-contador-wp/js/contador.js/wp-content/plugins/my-contador-wp/css/contador.css
Script Paths
/wp-content/plugins/my-contador-wp/js/contador.js

HTML / DOM Fingerprints

Shortcode Output
Su código de transacción es: <span id='codigoG'>Si ya ha terminado su transacción, por favor espere
FAQ

Frequently Asked Questions about My Contador lesr