
Post Pay Counter Security & Risk Analysis
wordpress.org/plugins/post-pay-counterEasily handle authors' payments on a multi-author blog by computing posts' remuneration basing on admin defined rules.
Is Post Pay Counter Safe to Use in 2026?
Generally Safe
Score 97/100Post Pay Counter has a strong security track record. Known vulnerabilities have been patched promptly.
The "post-pay-counter" v2.793 plugin exhibits a concerning security posture, primarily due to a large number of unprotected AJAX entry points and a history of critical vulnerabilities. The static analysis reveals a significant attack surface with 11 AJAX handlers, all of which lack authentication checks, presenting a prime opportunity for unauthorized actions. Furthermore, the presence of the `unserialize` function without clear input validation raises significant risks of deserialization vulnerabilities. The limited proper output escaping (12%) suggests a high likelihood of Cross-Site Scripting (XSS) flaws, which is corroborated by past vulnerability types.
Key Concerns
- Large attack surface without auth checks
- Dangerous function 'unserialize' used
- SQL queries without prepared statements
- Low percentage of properly escaped output
- Missing nonce checks on AJAX handlers
- History of critical vulnerabilities
- History of high severity vulnerabilities
- History of medium severity vulnerabilities
- Flows with unsanitized paths
Post Pay Counter Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Post Pay Counter <= 2.789 - Reflected Cross-Site Scripting
Post Pay Counter < 2.731 - Arbitrary Settings Change
Post Pay Counter < 2.731 - PHP Object Injection
Post Pay Counter Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Post Pay Counter Attack Surface
AJAX Handlers 11
WordPress Hooks 25
Scheduled Events 2
Maintenance & Trust
Post Pay Counter Maintenance & Trust
Maintenance Signals
Community Trust
Post Pay Counter Alternatives
WooPayments: Integrated WooCommerce Payments
woocommerce-payments
Securely accept credit and debit cards on your WooCommerce store. Manage payments without leaving your WordPress dashboard. Only with WooPayments.
WooCommerce PayPal Payments
woocommerce-paypal-payments
PayPal's latest payment processing solution. Accept PayPal, Pay Later, credit/debit cards, alternative digital wallets and bank accounts.
WooCommerce Stripe Payment Gateway
woocommerce-gateway-stripe
Accept debit and credit cards in 135+ currencies, many local methods like Alipay, ACH, and SEPA, and express checkout with Apple Pay and Google Pay.
WP Statistics – Simple, privacy-friendly Google Analytics alternative
wp-statistics
Get website traffic insights with GDPR/CCPA compliant, privacy-friendly analytics. Includes visitor data, stunning graphs, and no data sharing.
ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin)
google-analytics-dashboard-for-wp
Connects Google Analytics with your WordPress site. Displays stats to help you understand your users and site content on a whole new level!
Post Pay Counter Developer Profile
6 plugins · 3K total installs
How We Detect Post Pay Counter
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/post-pay-counter/css/ppc-admin.css/wp-content/plugins/post-pay-counter/css/ppc-frontend.css/wp-content/plugins/post-pay-counter/css/ppc-visitors-tracking.css/wp-content/plugins/post-pay-counter/js/ppc-admin.js/wp-content/plugins/post-pay-counter/js/ppc-frontend.js/wp-content/plugins/post-pay-counter/js/ppc-visitors-tracking.js/wp-content/plugins/post-pay-counter/js/ppc-admin.js/wp-content/plugins/post-pay-counter/js/ppc-frontend.js/wp-content/plugins/post-pay-counter/js/ppc-visitors-tracking.jspost-pay-counter/css/ppc-admin.css?ver=post-pay-counter/css/ppc-frontend.css?ver=post-pay-counter/css/ppc-visitors-tracking.css?ver=post-pay-counter/js/ppc-admin.js?ver=post-pay-counter/js/ppc-frontend.js?ver=post-pay-counter/js/ppc-visitors-tracking.js?ver=HTML / DOM Fingerprints
ppc-admin-settings-sectionppc-main-settings-containerppc-rowppc-settings-section-descriptionppc-input-groupppc-number-inputppc-text-inputppc-textarea+36 moreCopyright Stefano Ottolenghi 2013This program is free software: you can redistribute it and/or modifyThis program is distributed in the hope that it will be useful,You should have received a copy of the GNU General Public License+14 moredata-ppc-option-namedata-ppc-option-valuedata-ppc-option-typedata-ppc-setting-namedata-ppc-setting-valuedata-ppc-setting-type+7 moreppc_global_settingsPPC_AJAX_OBJECTppc_ajax_urlppc_noncePPC_install_functionsPPC_welcome+19 more