Personal Hit Counter Security & Risk Analysis

wordpress.org/plugins/personal-hit-counter

Inform the visitor, below the main content, how many times a specific Page, Post, or WooCommerce Product has been viewed by that visitor

40 active installs v2.0 PHP 7.4+ WP 5.5+ Updated Dec 7, 2025
hit-countertraffic-insightsvisitor-countervisitor-trackingwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Personal Hit Counter Safe to Use in 2026?

Generally Safe

Score 100/100

Personal Hit Counter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The static analysis of the 'personal-hit-counter' plugin v2.0 reveals a generally strong security posture. There are no identified dangerous functions, SQL injection vulnerabilities, file operations, or external HTTP requests. The use of prepared statements for all SQL queries is a significant strength. The plugin also incorporates nonce checks, which is a good practice for preventing CSRF attacks. However, the absence of capability checks and a complete lack of identified taint flows could indicate a limited scope of analysis or an overly simplistic codebase that might not handle all potential inputs securely.

The vulnerability history shows no recorded CVEs, which is a positive indicator. This lack of past vulnerabilities, coupled with the absence of critical or high-severity issues in the static analysis, suggests the plugin has been developed with security in mind or has had its vulnerabilities addressed. Despite the positive indicators, the 71% output escaping rate, while not alarmingly low, does leave room for potential cross-site scripting (XSS) vulnerabilities if the unescaped outputs are rendered in sensitive contexts. The attack surface appears minimal, which reduces the overall risk profile.

In conclusion, the 'personal-hit-counter' plugin v2.0 exhibits several good security practices, particularly concerning SQL and overall attack surface reduction. The lack of historical vulnerabilities is reassuring. The primary area for potential improvement lies in ensuring all output is properly escaped and that a more comprehensive taint analysis is performed to uncover any hidden input validation issues, especially given the absence of explicit capability checks on its entry points.

Key Concerns

  • Output escaping rate below 100%
  • No capability checks found
Vulnerabilities
None known

Personal Hit Counter Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Personal Hit Counter Release Timeline

v2.0Current
v1.0
Code Analysis
Analyzed Mar 16, 2026

Personal Hit Counter Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
5 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

71% escaped7 total outputs
Attack Surface

Personal Hit Counter Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
filterplugin_row_metapersonal-hit-counter.php:38
actionplugins_loadedpersonal-hit-counter.php:44
actionwp_enqueue_scriptspersonal-hit-counter.php:56
actionadd_meta_boxespersonal-hit-counter.php:69
actionsave_postpersonal-hit-counter.php:97
actiontemplate_redirectpersonal-hit-counter.php:134
filterthe_contentpersonal-hit-counter.php:188
Maintenance & Trust

Personal Hit Counter Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 7, 2025
PHP min version7.4
Downloads8K

Community Trust

Rating60/100
Number of ratings1
Active installs40
Developer Profile

Personal Hit Counter Developer Profile

Dear

17 plugins · 2K total installs

93
trust score
Avg Security Score
99/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Personal Hit Counter

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/personal-hit-counter/css/personal-hit-counter-styles.css
Version Parameters
personal-hit-counter/css/personal-hit-counter-styles.css?ver=

HTML / DOM Fingerprints

CSS Classes
personal-hit-counter-visit-info
Data Attributes
name="receptionistbytawhidurrahmandear_disable"value="1"
FAQ

Frequently Asked Questions about Personal Hit Counter