Posts and Products Views for WooCommerce Security & Risk Analysis

wordpress.org/plugins/posts-and-products-views

Track and display the view counts of WordPress posts and WooCommerce products in the admin panel and via shortcode.

100 active installs v2.1.1 PHP 5.2.4+ WP 4.9+ Updated Dec 9, 2025
counterpostsproductsviewswc
99
A · Safe
CVEs total1
Unpatched0
Last CVEDec 13, 2024
Safety Verdict

Is Posts and Products Views for WooCommerce Safe to Use in 2026?

Generally Safe

Score 99/100

Posts and Products Views for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Dec 13, 2024Updated 5mo ago
Risk Assessment

The "posts-and-products-views" plugin v2.1.1 demonstrates a generally good security posture based on the static analysis. It has a minimal attack surface, with only one shortcode as an entry point, and importantly, this entry point appears to be protected by a nonce and capability check. The plugin also adheres to secure coding practices by using prepared statements for all SQL queries and a high percentage of properly escaped output. There are no identified dangerous functions, file operations, or external HTTP requests, which significantly reduces the potential for common attack vectors.

While the static analysis reveals a strong adherence to secure coding principles, the vulnerability history presents a notable concern. The plugin has a past medium-severity Cross-site Scripting (XSS) vulnerability. Although it is currently unpatched, the fact that it's the only known CVE and is not marked as unpatched suggests it may have been addressed in a subsequent release or the analysis data might be slightly out of sync regarding the 'currently unpatched' status. However, any history of XSS warrants careful consideration, as such vulnerabilities can be exploited to compromise user sessions and inject malicious content.

In conclusion, the "posts-and-products-views" plugin v2.1.1 shows strengths in its limited attack surface and secure coding practices. The primary weakness lies in its historical vulnerability, specifically the XSS, which, despite being listed as unpatched in the past, highlights a potential area for risk. Users should ensure they are on the latest available version of the plugin to mitigate any past issues.

Key Concerns

  • Past medium severity XSS vulnerability history
Vulnerabilities
1 published

Posts and Products Views for WooCommerce Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-12448medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Posts and Products Views for WooCommerce <= 2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

Dec 13, 2024 Patched in 2.1.1 (33d)
Version History

Posts and Products Views for WooCommerce Release Timeline

v2.1.1Current
v2.11 CVE
v2.01 CVE
v1.41 CVE
v1.31 CVE
v1.21 CVE
v1.11 CVE
v1.01 CVE
Code Analysis
Analyzed Mar 16, 2026

Posts and Products Views for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
8 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

89% escaped9 total outputs
Attack Surface

Posts and Products Views for WooCommerce Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[papvfwc_views] posts-and-products-views-for-woocommerce.php:141
WordPress Hooks 10
actionadd_meta_boxesincludes\metabox.php:15
actionsave_postincludes\metabox.php:16
actioninitposts-and-products-views-for-woocommerce.php:133
actionadmin_menuposts-and-products-views-for-woocommerce.php:134
filtermanage_posts_columnsposts-and-products-views-for-woocommerce.php:135
filtermanage_pages_columnsposts-and-products-views-for-woocommerce.php:136
actionmanage_posts_custom_columnposts-and-products-views-for-woocommerce.php:137
actionmanage_pages_custom_columnposts-and-products-views-for-woocommerce.php:138
filterthe_contentposts-and-products-views-for-woocommerce.php:139
actionwoocommerce_before_add_to_cart_formposts-and-products-views-for-woocommerce.php:140
Maintenance & Trust

Posts and Products Views for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedDec 9, 2025
PHP min version5.2.4
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs100
Developer Profile

Posts and Products Views for WooCommerce Developer Profile

CoderPress

9 plugins · 4K total installs

85
trust score
Avg Security Score
95/100
Avg Patch Time
33 days
View full developer profile
Detection Fingerprints

How We Detect Posts and Products Views for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/posts-and-products-views/assets/css/style.css/wp-content/plugins/posts-and-products-views/assets/js/custom.js
Script Paths
/wp-content/plugins/posts-and-products-views/assets/js/custom.js
Version Parameters
posts-and-products-views/assets/css/style.css?ver=posts-and-products-views/assets/js/custom.js?ver=

HTML / DOM Fingerprints

CSS Classes
papvfwc-digit
Data Attributes
papvfwc_counter
Shortcode Output
<div class='
FAQ

Frequently Asked Questions about Posts and Products Views for WooCommerce