
Pretty Simple Progress meter Security & Risk Analysis
wordpress.org/plugins/pretty-simple-progress-meterPretty Simply Progress meter is a clean and fun way to share your tracked progress on everything!
Is Pretty Simple Progress meter Safe to Use in 2026?
Generally Safe
Score 85/100Pretty Simple Progress meter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "pretty-simple-progress-meter" v1.0 plugin exhibits a mixed security posture. On one hand, the absence of known vulnerabilities, a lack of external HTTP requests, and the use of prepared statements for SQL queries are positive indicators. The plugin also has a very small attack surface, with no AJAX handlers, REST API routes, shortcodes, or cron events, which limits potential entry points for attackers.
However, significant concerns arise from the static analysis. The presence of the `create_function` is a critical security anti-pattern, as it can lead to arbitrary code execution if user input is incorporated without proper sanitization, despite the zero reported taint flows in this analysis. Furthermore, a very low percentage of output escaping (16%) is a major red flag. This suggests that user-controlled data displayed on the frontend is likely to be vulnerable to Cross-Site Scripting (XSS) attacks, potentially allowing attackers to inject malicious scripts into a user's browser.
While the plugin has no recorded vulnerability history, this should not be interpreted as a guarantee of safety. The presence of `create_function` and widespread unescaped output are inherent weaknesses that could be exploited. The lack of nonce checks and minimal capability checks on the limited entry points (though there are none recorded) further contribute to a less secure design. The plugin would benefit from a thorough review and remediation of these identified code quality issues.
Key Concerns
- Use of create_function (dangerous function)
- Low percentage of properly escaped output
- No nonce checks on potential entry points
- Limited capability checks
Pretty Simple Progress meter Security Vulnerabilities
Pretty Simple Progress meter Release Timeline
Pretty Simple Progress meter Code Analysis
Dangerous Functions Found
Output Escaping
Pretty Simple Progress meter Attack Surface
WordPress Hooks 4
Maintenance & Trust
Pretty Simple Progress meter Maintenance & Trust
Maintenance Signals
Community Trust
Pretty Simple Progress meter Alternatives
Ultimeter
ultimeter
Ultimeter - the Ultimate Progress and Goals Meter
Author WIP Progress Bar
author-work-in-progress-bar
Tested up to 6.7.1 The WIP Progress Bar plugin allows writers and authors to display beautiful progress bars on their WordPress websites via a Widget …
Dave’s Whizmatronic Widgulating Calibrational Scribometer
daves-whizmatronic-widgulating-calibrational-scribometer
The Scribometer allows writers to track and display their writing progress in their sidebar.
Goal Progress Tracker
goal-progress-tracker
A beautiful and interactive goal progress tracker that displays progress as a horizontal thermometer with customizable gradient colors.
ProgPress
progpress
Easily insert progress meters into your content and/or sidebars.
Pretty Simple Progress meter Developer Profile
1 plugin · 10 total installs
How We Detect Pretty Simple Progress meter
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/pretty-simple-progress-meter/css/psp_styles.phpHTML / DOM Fingerprints
prettysimpleprogresswidgetpspDescriptionpspDetailpspMeterpspBarpspProgresspspImgPretty Simple Progress Styles, YARwidget_prettysimpleprogressdata-widget-id