Posts Character Count Admin Security & Risk Analysis

wordpress.org/plugins/posts-character-count-admin

Displays a column with the character count for each post in the Manage Posts SubPanel and in the Edit Posts SubPanel.

1K active installs v2.1 PHP + WP 3.9+ Updated Jul 21, 2014
admincharacter-countcharacter-lengthcountposts
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Posts Character Count Admin Safe to Use in 2026?

Generally Safe

Score 85/100

Posts Character Count Admin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The plugin 'posts-character-count-admin' v2.1 exhibits an excellent security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the potential attack surface. Furthermore, the code signals indicate no dangerous functions, all SQL queries use prepared statements, and there are no file operations or external HTTP requests. This suggests a well-secured codebase with no obvious direct vulnerabilities identified through static analysis or taint flows.

The vulnerability history also supports this positive assessment, with no known CVEs or recorded past vulnerabilities. This suggests a history of secure development practices or a lack of previous exploitation. However, the most significant concern arising from the static analysis is the lack of output escaping. With one total output and 0% properly escaped, there is a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. This is a critical oversight that could be exploited by attackers to inject malicious scripts into the WordPress admin area, impacting users who view the affected output.

In conclusion, while the plugin demonstrates strong security fundamentals by minimizing attack vectors and employing secure coding practices for database interactions, the unescaped output presents a clear and present danger. This weakness, if unaddressed, could undermine the overall security of the plugin. The absence of past vulnerabilities is a positive indicator, but it does not negate the immediate risk posed by the XSS vulnerability.

Key Concerns

  • 100% of outputs are unescaped
Vulnerabilities
None known

Posts Character Count Admin Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Posts Character Count Admin Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped1 total outputs
Attack Surface

Posts Character Count Admin Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actionadmin_initinc\class-posts-character-count-admin.php:6
actionload-edit.phpinc\class-posts-character-count-admin.php:11
actionload-post.phpinc\class-posts-character-count-admin.php:14
filtermanage_posts_columnsinc\class-posts-character-count-admin.php:20
actionmanage_posts_custom_columninc\class-posts-character-count-admin.php:21
filtermanage_pages_columnsinc\class-posts-character-count-admin.php:24
actionmanage_pages_custom_columninc\class-posts-character-count-admin.php:25
actionadmin_footerinc\class-posts-character-count-admin.php:30
actionplugins_loadedposts-character-count-admin.php:36
Maintenance & Trust

Posts Character Count Admin Maintenance & Trust

Maintenance Signals

WordPress version tested3.9.40
Last updatedJul 21, 2014
PHP min version
Downloads17K

Community Trust

Rating86/100
Number of ratings3
Active installs1K
Developer Profile

Posts Character Count Admin Developer Profile

Jan Teriete

3 plugins · 1K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Posts Character Count Admin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/posts-character-count-admin/css/style.css/wp-content/plugins/posts-character-count-admin/js/posts-character-count-admin.js
Script Paths
/wp-content/plugins/posts-character-count-admin/js/posts-character-count-admin.js
Version Parameters
posts-character-count-admin/css/style.css?ver=posts-character-count-admin/js/posts-character-count-admin.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Posts Character Count Admin