
Posts and Products Views for WooCommerce Security & Risk Analysis
wordpress.org/plugins/posts-and-products-viewsTrack and display the view counts of WordPress posts and WooCommerce products in the admin panel and via shortcode.
Is Posts and Products Views for WooCommerce Safe to Use in 2026?
Generally Safe
Score 99/100Posts and Products Views for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "posts-and-products-views" plugin v2.1.1 demonstrates a generally good security posture based on the static analysis. It has a minimal attack surface, with only one shortcode as an entry point, and importantly, this entry point appears to be protected by a nonce and capability check. The plugin also adheres to secure coding practices by using prepared statements for all SQL queries and a high percentage of properly escaped output. There are no identified dangerous functions, file operations, or external HTTP requests, which significantly reduces the potential for common attack vectors.
While the static analysis reveals a strong adherence to secure coding principles, the vulnerability history presents a notable concern. The plugin has a past medium-severity Cross-site Scripting (XSS) vulnerability. Although it is currently unpatched, the fact that it's the only known CVE and is not marked as unpatched suggests it may have been addressed in a subsequent release or the analysis data might be slightly out of sync regarding the 'currently unpatched' status. However, any history of XSS warrants careful consideration, as such vulnerabilities can be exploited to compromise user sessions and inject malicious content.
In conclusion, the "posts-and-products-views" plugin v2.1.1 shows strengths in its limited attack surface and secure coding practices. The primary weakness lies in its historical vulnerability, specifically the XSS, which, despite being listed as unpatched in the past, highlights a potential area for risk. Users should ensure they are on the latest available version of the plugin to mitigate any past issues.
Key Concerns
- Past medium severity XSS vulnerability history
Posts and Products Views for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Posts and Products Views for WooCommerce <= 2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
Posts and Products Views for WooCommerce Release Timeline
Posts and Products Views for WooCommerce Code Analysis
Output Escaping
Posts and Products Views for WooCommerce Attack Surface
Shortcodes 1
WordPress Hooks 10
Maintenance & Trust
Posts and Products Views for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Posts and Products Views for WooCommerce Alternatives
Light Views Counter – Fast, Scalable View Counter for High-Traffic Sites
light-views-counter
Lightweight and fast post view counter with smart tracking, built for high-traffic sites and large post databases.
WP Views Counter
wpecounter
Fast, lightweight post views counter. Display views in admin, blocks or shortcodes — no tracking scripts required.
Post Views Stats Counter
post-views-stats-counter
This plugin will display how many times post and page viewed. It shows total view of access per day, week, month, and all days.
Init View Count – AI-Powered, Trending, REST API
init-view-count
Count post views accurately via REST API with customizable display. Lightweight, fast, and extensible. Includes shortcode with multiple layouts.
DP Post Views Counter
dp-post-views
The plugin show how many people have viewed an article on the site.
Posts and Products Views for WooCommerce Developer Profile
9 plugins · 4K total installs
How We Detect Posts and Products Views for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/posts-and-products-views/assets/css/style.css/wp-content/plugins/posts-and-products-views/assets/js/custom.js/wp-content/plugins/posts-and-products-views/assets/js/custom.jsposts-and-products-views/assets/css/style.css?ver=posts-and-products-views/assets/js/custom.js?ver=HTML / DOM Fingerprints
papvfwc-digitpapvfwc_counter<div class='