
Post Views Stats Counter Security & Risk Analysis
wordpress.org/plugins/post-views-stats-counterThis plugin will display how many times post and page viewed. It shows total view of access per day, week, month, and all days.
Is Post Views Stats Counter Safe to Use in 2026?
Generally Safe
Score 85/100Post Views Stats Counter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "post-views-stats-counter" plugin v1.1.7 exhibits a generally strong security posture, primarily due to the complete absence of dangerous functions, external requests, and file operations. The plugin also demonstrates good practices by exclusively using prepared statements for its SQL queries and including at least one nonce and capability check. However, there are areas for improvement. The static analysis reveals a concerning taint flow with unsanitized paths identified as high severity, indicating a potential for vulnerabilities if this flow involves user-controlled input that is not adequately validated or sanitized before being used in a sensitive operation. Furthermore, while 96 outputs are accounted for, only 65% are properly escaped, leaving a significant portion of output potentially vulnerable to cross-site scripting (XSS) attacks.
The plugin's vulnerability history is spotless, with no known CVEs recorded. This is a positive indicator, suggesting that the plugin has either been well-maintained or has not yet been a target for widespread exploitation. However, the absence of past vulnerabilities does not guarantee future security, especially given the identified taint flow and output escaping issues. In conclusion, while the plugin scores well on several critical security fronts like SQL injection prevention and controlled attack surface, the high-severity taint flow and the substantial percentage of unescaped output represent tangible risks that require attention. The lack of a history of vulnerabilities is a strength, but it should not overshadow the need to address the identified code-level concerns.
Key Concerns
- High severity taint flow with unsanitized path
- Significant percentage of unescaped output
Post Views Stats Counter Security Vulnerabilities
Post Views Stats Counter Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Post Views Stats Counter Attack Surface
WordPress Hooks 5
Maintenance & Trust
Post Views Stats Counter Maintenance & Trust
Maintenance Signals
Community Trust
Post Views Stats Counter Alternatives
Easy Post View Counter
easy-post-view-counter
With this plugin you can see how many views a single post has.
DP Post Views Counter
dp-post-views
The plugin show how many people have viewed an article on the site.
WP-PostViews
wp-postviews
Enables you to display how many times a post/page had been viewed.
WP Views Counter
wpecounter
Fast, lightweight post views counter. Display views in admin, blocks or shortcodes — no tracking scripts required.
WP-PostViews Plus
wp-postviews-plus
Enables You To Display How Many Times A Post Had Been Viewed By User Or Bot.
Post Views Stats Counter Developer Profile
5 plugins · 7K total installs
How We Detect Post Views Stats Counter
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/post-views-stats-counter/js/pvscounter.js/wp-content/plugins/post-views-stats-counter/css/pvscounter.css/wp-content/plugins/post-views-stats-counter/js/pvscounter.jspost-views-stats-counter/js/pvscounter.js?ver=post-views-stats-counter/css/pvscounter.css?ver=