
Post-counter Security & Risk Analysis
wordpress.org/plugins/post-counterWrites in the slidebar the numbers of your posts
Is Post-counter Safe to Use in 2026?
Generally Safe
Score 85/100Post-counter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "post-counter" plugin v0.2 exhibits a generally strong security posture based on the provided static analysis. There are no identified dangerous functions, file operations, or external HTTP requests, and importantly, all SQL queries utilize prepared statements. The complete absence of known CVEs and a clean vulnerability history further suggest a well-maintained and secure plugin. However, a significant concern arises from the "Output escaping" signal, indicating that 100% of the 8 identified outputs are not properly escaped. This is a critical weakness that could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is directly outputted without sanitization. The lack of any identified attack surface points (AJAX, REST API, shortcodes, cron) is positive, but the absence of nonce and capability checks, while not directly exploitable given the lack of exposed entry points in this version, represents a missed opportunity for robust security practices.
Key Concerns
- All outputs are unescaped
- No nonce checks implemented
- No capability checks implemented
Post-counter Security Vulnerabilities
Post-counter Code Analysis
Output Escaping
Post-counter Attack Surface
WordPress Hooks 1
Maintenance & Trust
Post-counter Maintenance & Trust
Maintenance Signals
Community Trust
Post-counter Alternatives
Display Site Numbers
display-site-numbers
Widget and shortcode to display all relevant site content numbers
GA-PVcounter
ga-pvcounter
Google Analytics PageView counter and Popular posts, Recent posts widget
RB Post Views Widget
rb-post-views-widget
Display the most viewed posts on your website using a simple, lightweight widget.
WP Views Counter
wpecounter
Fast, lightweight post views counter. Display views in admin, blocks or shortcodes — no tracking scripts required.
Light Views Counter – Fast, Scalable View Counter for High-Traffic Sites
light-views-counter
Lightweight and fast post view counter with smart tracking, built for high-traffic sites and large post databases.
Post-counter Developer Profile
10 plugins · 220 total installs
How We Detect Post-counter
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/post-counter/langHTML / DOM Fingerprints
widget_featured_entries