
PostTally Security & Risk Analysis
wordpress.org/plugins/posttallyA plugin that adds a [post_count] shortcode to display the total number of published posts.
Is PostTally Safe to Use in 2026?
Generally Safe
Score 100/100PostTally has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'posttally' v1.0.0 plugin exhibits a strong security posture based on the provided static analysis. The complete absence of dangerous functions, SQL queries without prepared statements, and the proper escaping of all outputs are commendable practices. Furthermore, the plugin has no recorded vulnerabilities, including critical or high severity CVEs, and no recent security issues have been reported. This suggests a well-developed and conscientiously maintained plugin that prioritizes secure coding standards.
While the static analysis indicates a very low risk profile, it's important to note the presence of a single shortcode as the only entry point. Although it's reported as unprotected, the lack of any other identified attack vectors or taint flows mitigates this concern significantly in the current version. The absence of nonce checks and capability checks, while common in simpler plugins, could become a concern if the shortcode's functionality were to expand or handle sensitive data in future versions. However, based solely on the current data, the plugin appears to be secure.
In conclusion, 'posttally' v1.0.0 demonstrates excellent security hygiene, with no identified vulnerabilities or significant risks in its code. The plugin's minimal attack surface and adherence to secure coding practices make it appear safe for use. The only minor area for potential future attention would be the reinforcement of access controls around its shortcode functionality if its scope were to increase.
Key Concerns
- Unprotected shortcode identified
- Missing nonce checks
- Missing capability checks
PostTally Security Vulnerabilities
PostTally Release Timeline
PostTally Code Analysis
Output Escaping
PostTally Attack Surface
Shortcodes 1
WordPress Hooks 1
Maintenance & Trust
PostTally Maintenance & Trust
Maintenance Signals
Community Trust
PostTally Alternatives
User Stats
user-stats
User Stats provides an easy way to see at a glance stats about your users, including: post count, post views, article costs, costs per 1000 views and …
TK Shortcode Link
tk-shortcode-link
Create links with a shortcode. It's that simple.
Post Count Tracker
post-count-tracker
Displays the total number of posts at the end of each post's content.
Advance User Post CRUD
advance-user-post-crud
Advance User CRUD lets you see different posts, pages and attachments created by a user. And lets you manage the user generated posts.
PostAge Tracker
postage-tracker
A lightweight plugin that adds a [post_age] shortcode to display how old a post is (e.g., "3 days ago").
PostTally Developer Profile
7 plugins · 380 total installs
How We Detect PostTally
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
[post_count]