Posts Number Widget Security & Risk Analysis

wordpress.org/plugins/posts-number-widget

The widget display number of posts.

10 active installs v1.2 PHP + WP 3.0+ Updated Jun 24, 2019
widget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Posts Number Widget Safe to Use in 2026?

Generally Safe

Score 85/100

Posts Number Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The static analysis of 'posts-number-widget' v1.2 reveals a generally strong security posture. The plugin reports zero entry points, including AJAX handlers, REST API routes, shortcodes, and cron events, which significantly limits the potential attack surface. Furthermore, the absence of dangerous functions, file operations, external HTTP requests, and the use of prepared statements for all SQL queries are excellent security practices. The plugin also has no recorded vulnerability history, suggesting a history of secure development or a lack of targeting. However, a significant concern is the low percentage (29%) of properly escaped output. This indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, where malicious scripts could be injected through user-supplied data that is not adequately sanitized before being displayed back to users. While the plugin is free of known CVEs and critical taint analysis findings, the output escaping issue is a tangible risk that needs immediate attention.

Key Concerns

  • Low output escaping percentage
Vulnerabilities
None known

Posts Number Widget Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Posts Number Widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
10
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

29% escaped14 total outputs
Attack Surface

Posts Number Widget Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionwidgets_initposts-number-widget.php:59
Maintenance & Trust

Posts Number Widget Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedJun 24, 2019
PHP min version
Downloads2K

Community Trust

Rating80/100
Number of ratings2
Active installs10
Developer Profile

Posts Number Widget Developer Profile

sysbird

4 plugins · 200 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Posts Number Widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/posts-number-widget/css/posts-number-widget.css
Version Parameters
posts-number-widget/css/posts-number-widget.css?ver=

HTML / DOM Fingerprints

Data Attributes
id="posts-number-widget-unit"name="posts-number-widget-unit"id="posts-number-widget-title"name="posts-number-widget-title"
FAQ

Frequently Asked Questions about Posts Number Widget