
Post Popularity Chart Widget Security & Risk Analysis
wordpress.org/plugins/post-popularity-chart-widget-litePost Popularity Chart Widget, by which you display a graph with statistics of visits of any article on your site.
Is Post Popularity Chart Widget Safe to Use in 2026?
Generally Safe
Score 85/100Post Popularity Chart Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of "post-popularity-chart-widget-lite" v1.0.1 reveals a plugin with a minimal attack surface. Notably, there are no apparent AJAX handlers, REST API routes, shortcodes, or cron events, which significantly reduces the avenues for external exploitation. However, the code analysis flags several concerning practices. The presence of the `create_function` is a high-risk indicator, as it can lead to arbitrary code execution if user-supplied data is passed to it. Furthermore, the complete lack of prepared statements for SQL queries (100% of 7 queries) and the absence of output escaping (0% properly escaped for 46 outputs) are critical security weaknesses that could easily lead to SQL injection and cross-site scripting (XSS) vulnerabilities, respectively. The plugin's vulnerability history is clean, with no recorded CVEs. While this is a positive sign, it doesn't negate the significant risks identified in the current code. The absence of nonces and capability checks on the (albeit non-existent) entry points also contributes to a generally insecure coding standard. In conclusion, while the plugin has a small attack surface, the identified code vulnerabilities, particularly the use of `create_function`, raw SQL, and unescaped output, represent substantial security risks that demand immediate attention.
Key Concerns
- Use of create_function
- Raw SQL queries (no prepared statements)
- Unescaped output
- Missing nonce checks
- Missing capability checks
Post Popularity Chart Widget Security Vulnerabilities
Post Popularity Chart Widget Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Post Popularity Chart Widget Attack Surface
WordPress Hooks 1
Maintenance & Trust
Post Popularity Chart Widget Maintenance & Trust
Maintenance Signals
Community Trust
Post Popularity Chart Widget Alternatives
Charts and Graphs for Elementor
charts-and-graphs-for-elementor
Create beautiful, interactive charts with Graphs & Charts
Simple Graph
simple-graph
Draws a line graph of single set of date related data. Graph can be made public (i.e. sidebar widget or static page) and the data can be edited throug …
Data Diagrams: Visual Chart Editor for WordPress
data-diagrams
Visual Editor for 33+ free responsive SVG data charts - as easy as adding an image. No technical skills needed. Live data. No external API calls.
Visualizer: Tables and Charts Manager for WordPress
visualizer
A simple yet powerful WordPress chart plugin to effortlessly create and embed responsive charts & tables into your site, supporting multiple data …
Graphina – Charts and Graphs For Elementor
graphina-elementor-charts-and-graphs
Most Powerful Data visualization plugin for WordPress Elementor. The easiest way to build gorgeous Charts & Graphs on your Elementor website.
Post Popularity Chart Widget Developer Profile
6 plugins · 80 total installs
How We Detect Post Popularity Chart Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/post-popularity-chart-widget-lite/style.css/wp-content/plugins/post-popularity-chart-widget-lite/script.js/wp-content/plugins/post-popularity-chart-widget-lite/script.jspost-popularity-chart-widget-lite/style.css?ver=post-popularity-chart-widget-lite/script.js?ver=HTML / DOM Fingerprints
post-popularity-chart-widget-lite-chartid="post_popularity_graph_widget_id"name="post_popularity_graph_widget_name"value="chartcolor"name="chartcolor"value="backgroundcolor"name="backgroundcolor"+14 morewindow.post_popularity_chart_widget_lite_settings