
Plugin Register Security & Risk Analysis
wordpress.org/plugins/plugin-registerFor Wordpress plugin developers: keep a register of when and where your plugins are activated.
Is Plugin Register Safe to Use in 2026?
Generally Safe
Score 85/100Plugin Register has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "plugin-register" v0.6.5 plugin exhibits a mixed security posture. While it has a zero-known CVE history and a seemingly limited attack surface with no direct entry points like AJAX handlers, REST API routes, or shortcodes, significant concerns arise from the static code analysis. The presence of `create_function`, a notoriously insecure function that can lead to arbitrary code execution, is a critical red flag. Furthermore, a concerning 0% of outputs are properly escaped, meaning any dynamic data displayed to users is vulnerable to cross-site scripting (XSS) attacks. The taint analysis revealing one flow with unsanitized paths further amplifies these risks, particularly a high-severity flow, suggesting a potential for privilege escalation or data leakage if that path is exploitable. The plugin also lacks nonce checks and has only one capability check, leaving many operations potentially vulnerable to CSRF attacks. While the high percentage of prepared statements for SQL queries is a positive, it does not mitigate the risks associated with unescaped output and insecure function usage.
Key Concerns
- Dangerous function: create_function used
- 0% output escaping
- High severity taint flow
- 0 nonce checks
- Unsanitized path in taint flow
Plugin Register Security Vulnerabilities
Plugin Register Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Plugin Register Attack Surface
WordPress Hooks 8
Scheduled Events 1
Maintenance & Trust
Plugin Register Maintenance & Trust
Maintenance Signals
Community Trust
Plugin Register Alternatives
Post Views Counter
post-views-counter
Post Views Counter allows you to collect and display how many times a post, page, or other content has been viewed in a simple, fast and reliable way.
Wp Social Login and Register Social Counter
wp-social
Wp social lets you add social login, social counter, and social share buttons of different styles to your WordPress website.
StatCounter – Free Real Time Visitor Stats
official-statcounter-plugin-for-wordpress
StatCounter.com powered real-time detailed stats about the visitors to your blog.
Visitor Traffic Real Time Statistics
visitors-traffic-real-time-statistics
This plugin will help you to track your visitors, browsers, operating systems, visits and much more in one dashboard page.
WPS Visitor Counter
wps-visitor-counter
Display website visitor statistics with widget, shortcode, and Gutenberg block support.
Plugin Register Developer Profile
11 plugins · 460 total installs
How We Detect Plugin Register
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
pluginregister_dashboard_report