
Display Simple Post View Count Security & Risk Analysis
wordpress.org/plugins/simple-post-counter-displaySimple Post Counter Display plugin will display post count.
Is Display Simple Post View Count Safe to Use in 2026?
Generally Safe
Score 85/100Display Simple Post View Count has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'simple-post-counter-display' plugin v1.0.0 exhibits a mixed security posture. While it avoids dangerous functions, raw SQL, and external HTTP requests, significant concerns arise from its attack surface and output sanitization. The presence of one unprotected AJAX handler represents a clear entry point for potential attacks, especially when combined with a low rate of proper output escaping. Taint analysis, although limited, did reveal flows with unsanitized paths, which, coupled with the lack of proper input validation suggested by the unprotected AJAX handler and zero capability checks, could be leveraged to inject malicious data if specific conditions are met.
The plugin's vulnerability history is notably clean, with no recorded CVEs. This absence of past vulnerabilities is a positive indicator, suggesting either careful development or limited exposure. However, the static analysis findings, particularly the unprotected AJAX handler and poor output escaping, represent inherent weaknesses that could be exploited regardless of past vulnerability history. The plugin has strengths in its avoidance of common risky practices like raw SQL queries, but the identified attack surface and sanitization issues are significant enough to warrant caution.
Key Concerns
- Unprotected AJAX handler
- Low output escaping rate
- Unsanitized paths in taint flows
- No capability checks
- No nonce checks on AJAX
Display Simple Post View Count Security Vulnerabilities
Display Simple Post View Count Code Analysis
Output Escaping
Data Flow Analysis
Display Simple Post View Count Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 9
Maintenance & Trust
Display Simple Post View Count Maintenance & Trust
Maintenance Signals
Community Trust
Display Simple Post View Count Alternatives
No alternatives data available yet.
Display Simple Post View Count Developer Profile
1 plugin · 10 total installs
How We Detect Display Simple Post View Count
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/simple-post-counter-display/css/style.csssimple-post-counter-display/css/style.css?ver=HTML / DOM Fingerprints
spcd_count_discls_can_you_dvcposition_show_hideposition_pvddata-form_submitdata-actionspcd_frontend_cssspcd_count_textspcd_can_you_dvcspcd_position_pvdspcd_post_type/wp-json/admin-ajax.php<div class="cls_ spcd_count_dis"><span>