
Posts Character Count Admin Security & Risk Analysis
wordpress.org/plugins/posts-character-count-adminDisplays a column with the character count for each post in the Manage Posts SubPanel and in the Edit Posts SubPanel.
Is Posts Character Count Admin Safe to Use in 2026?
Generally Safe
Score 85/100Posts Character Count Admin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'posts-character-count-admin' v2.1 exhibits an excellent security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the potential attack surface. Furthermore, the code signals indicate no dangerous functions, all SQL queries use prepared statements, and there are no file operations or external HTTP requests. This suggests a well-secured codebase with no obvious direct vulnerabilities identified through static analysis or taint flows.
The vulnerability history also supports this positive assessment, with no known CVEs or recorded past vulnerabilities. This suggests a history of secure development practices or a lack of previous exploitation. However, the most significant concern arising from the static analysis is the lack of output escaping. With one total output and 0% properly escaped, there is a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. This is a critical oversight that could be exploited by attackers to inject malicious scripts into the WordPress admin area, impacting users who view the affected output.
In conclusion, while the plugin demonstrates strong security fundamentals by minimizing attack vectors and employing secure coding practices for database interactions, the unescaped output presents a clear and present danger. This weakness, if unaddressed, could undermine the overall security of the plugin. The absence of past vulnerabilities is a positive indicator, but it does not negate the immediate risk posed by the XSS vulnerability.
Key Concerns
- 100% of outputs are unescaped
Posts Character Count Admin Security Vulnerabilities
Posts Character Count Admin Code Analysis
Output Escaping
Posts Character Count Admin Attack Surface
WordPress Hooks 9
Maintenance & Trust
Posts Character Count Admin Maintenance & Trust
Maintenance Signals
Community Trust
Posts Character Count Admin Alternatives
Sortable Word Count Reloaded
sortable-word-count-reloaded
Adds a sortable column to the posts and pages admin list with the word count of each page/post.
Admins Post Statistics
admins-post-statistics
This plugin counts views of admin, editor and author posts' also creates sub menu Admin Statistics under Posts to see number of posts they' …
Smash Balloon Social Post Feed – Simple Social Feeds for WordPress
custom-facebook-feed
Formerly "Custom Facebook Feed". Display completely customizable Facebook feeds of a Facebook page. Supports Facebook oEmbeds.
Reading Time WP
reading-time-wp
Reading Time WP creates an estimated reading time of your posts that is inserted above the content or by using a shortcode.
WP Admin UI Customize
wp-admin-ui-customize
Customize the management screen UI.
Posts Character Count Admin Developer Profile
3 plugins · 1K total installs
How We Detect Posts Character Count Admin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/posts-character-count-admin/css/style.css/wp-content/plugins/posts-character-count-admin/js/posts-character-count-admin.js/wp-content/plugins/posts-character-count-admin/js/posts-character-count-admin.jsposts-character-count-admin/css/style.css?ver=posts-character-count-admin/js/posts-character-count-admin.js?ver=