
Network Sites Counts Dashboard Widget Security & Risk Analysis
wordpress.org/plugins/network-sites-counts-dashboard-widgetDisplay a list of post counts for all your sites in your network.
Is Network Sites Counts Dashboard Widget Safe to Use in 2026?
Generally Safe
Score 100/100Network Sites Counts Dashboard Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "network-sites-counts-dashboard-widget" v1.0.0 exhibits a strong adherence to several secure coding practices. The absence of any known CVEs in its history and the lack of critical or high-severity findings in static analysis, including taint analysis, are positive indicators. The plugin also shows good handling of SQL queries by exclusively using prepared statements, and no external HTTP requests or file operations are present, which reduces common attack vectors.
However, there are notable areas for improvement that present potential security concerns. The most significant issue is the complete lack of capability checks and nonce checks. This means that if any entry points were discovered or introduced in future versions, they would likely be unprotected, allowing unauthorized actions. Furthermore, the low percentage of properly escaped output (14%) suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data could be rendered directly in the browser without proper sanitization. The absence of an attack surface doesn't negate the risk associated with these fundamental security mechanisms being entirely missing.
In conclusion, while the plugin currently appears to be free of known vulnerabilities and avoids certain risky practices like raw SQL or external requests, the severe deficiencies in authentication and output escaping create a significant latent risk. Future development must prioritize implementing robust capability and nonce checks, and significantly improve output escaping to mitigate potential XSS attacks.
Key Concerns
- No capability checks implemented
- No nonce checks implemented
- Low output escaping percentage (14%)
Network Sites Counts Dashboard Widget Security Vulnerabilities
Network Sites Counts Dashboard Widget Code Analysis
SQL Query Safety
Output Escaping
Network Sites Counts Dashboard Widget Attack Surface
WordPress Hooks 4
Maintenance & Trust
Network Sites Counts Dashboard Widget Maintenance & Trust
Maintenance Signals
Community Trust
Network Sites Counts Dashboard Widget Alternatives
Unconfirmed
unconfirmed
Allows WordPress admins to manage unactivated users, by activating them manually, deleting their pending registrations, or resending the activation em …
Network Username Restrictions Override
network-username-restrictions-override
Override restrictions on WordPress network usernames.
Plugin Activation Status
plugin-activation-status
Scans a multisite or multi-network installation to identify all plugins that are active or not.
WP Over Network
wp-over-network
Add ability to get posts from over your network sites. Supports widget, shortcode, and customizable original function.
Multisite Enhancements
multisite-enhancements
Enhance Multisite for Network Admins with different topics
Network Sites Counts Dashboard Widget Developer Profile
9 plugins · 370 total installs
How We Detect Network Sites Counts Dashboard Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/network-sites-counts-dashboard-widget/includes/Network_Sites_Counts_Data.phpHTML / DOM Fingerprints
widefat