
Post Views for Jetpack Security & Risk Analysis
wordpress.org/plugins/post-views-for-jetpackDisplay the number of views for each one of your posts, as recorded by Jetpack Stats.
Is Post Views for Jetpack Safe to Use in 2026?
Generally Safe
Score 92/100Post Views for Jetpack has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "post-views-for-jetpack" v1.5.0 demonstrates a generally strong security posture based on the provided static analysis. The absence of dangerous functions, external HTTP requests, and file operations is positive. Furthermore, all SQL queries are properly prepared, and the attack surface is minimal, with no unprotected entry points. However, there are areas for improvement. A significant concern is the lack of nonce and capability checks across all entry points, including the single shortcode. This leaves the plugin vulnerable to potential CSRF attacks and unauthorized actions if the shortcode's functionality can be exploited. While the current output escaping is at 75%, the remaining 25% could still lead to XSS vulnerabilities if user-supplied data is being outputted without proper sanitization.
The vulnerability history is a significant strength, showing no recorded CVEs. This suggests a history of stable and secure development or a lack of past exploitation. However, relying solely on this history can be misleading; the absence of past vulnerabilities does not guarantee future security, especially when critical security controls like nonce and capability checks are missing. In conclusion, the plugin is well-built in many areas, particularly regarding data handling and SQL security. The primary weakness lies in the insufficient input validation and authorization checks at its entry points, which represents a tangible risk despite a clean vulnerability history.
Key Concerns
- No nonce checks on entry points
- No capability checks on entry points
- Unescaped output (25% of outputs)
Post Views for Jetpack Security Vulnerabilities
Post Views for Jetpack Release Timeline
Post Views for Jetpack Code Analysis
Output Escaping
Post Views for Jetpack Attack Surface
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
Post Views for Jetpack Maintenance & Trust
Maintenance Signals
Community Trust
Post Views for Jetpack Alternatives
Post views Stats
post-views-stats
This plugins will count each post/page views by visitor.
Jetpack Lite
jetpack-lite
Prevents Jetpack from loading any modules except for Stats and WP.me Shortlinks modules. Jetpack is required!
Jetpack Post Views
jetpack-post-views
Display your most popular posts using Jetpack stats.
Advance User Post CRUD
advance-user-post-crud
Advance User CRUD lets you see different posts, pages and attachments created by a user. And lets you manage the user generated posts.
Statify
statify
Visitor statistics for WordPress with focus on data protection, transparency and clarity. Perfect as a widget in your WordPress Dashboard.
Post Views for Jetpack Developer Profile
11 plugins · 2K total installs
How We Detect Post Views for Jetpack
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
post-views-for-jetpack/jp-post-views.php?ver=HTML / DOM Fingerprints
/wp-json/wp/v2/posts?_fields=viewsno views%s view%s views