
Simple product counter Security & Risk Analysis
wordpress.org/plugins/simple-product-counterNotice with product sales and views for certain period.
Is Simple product counter Safe to Use in 2026?
Generally Safe
Score 85/100Simple product counter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "simple-product-counter" plugin, version 2.2.0, exhibits a mixed security posture. On one hand, it demonstrates an exceptionally small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events. This lack of direct entry points significantly limits potential attack vectors. Furthermore, the plugin has no recorded vulnerability history, suggesting a history of responsible development or a lack of past scrutiny.
However, the static analysis reveals significant concerns within the code itself. The presence of eight dangerous function calls, specifically `unserialize`, is a major red flag. `unserialize` is inherently risky as it can lead to code execution if used with untrusted data. Compounding this, the plugin does not utilize prepared statements for its single SQL query, increasing the risk of SQL injection. The taint analysis, though limited in scope, found flows with unsanitized paths, indicating potential weaknesses where user-supplied data might not be properly validated or escaped before being used in sensitive operations. The fact that 44% of output is not properly escaped also poses a risk of cross-site scripting (XSS) vulnerabilities.
Despite the promising lack of external vulnerabilities and a small attack surface, the internal code quality raises serious concerns. The heavy reliance on `unserialize` without apparent sanitization, raw SQL queries, and unescaped output creates a notable risk. Developers should prioritize addressing these internal code issues to improve the plugin's overall security.
Key Concerns
- Dangerous function calls (unserialize)
- SQL queries without prepared statements
- Output escaping is not fully implemented
- Taint analysis shows unsanitized paths
- No nonce checks
- No capability checks
Simple product counter Security Vulnerabilities
Simple product counter Release Timeline
Simple product counter Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Simple product counter Attack Surface
WordPress Hooks 10
Maintenance & Trust
Simple product counter Maintenance & Trust
Maintenance Signals
Community Trust
Simple product counter Alternatives
BRK Product View Count for WooCommerce
brk-product-view-count-for-woocommerce
BRK Product View Count for WooCommerce displays real-time or manually configured sales view data on product pages, enhancing customer engagement.
Sales Countdown Timer
sales-countdown-timer
Create versatile countdown timers for your WordPress site and WooCommerce products, including progress bars and upcoming sale countdowns.
Sales Count Manager for WooCommerce
wc-sales-count-manager
Display sold item count for each product in WooCommerce, customize the counter, and add social share buttons for better engagement.
Show Product Sales Count for WooCommerce
wpb-woocommerce-show-sales-numbers
Show product sales count on your WooCommerce store. A simple plugin to boost trust and increase conversions.
Country Sales Report For WooCommerce
ni-country-sales-report-for-woocommerce
Ni Country Sales Report for WooCommerce provides comprehensive sales reports and analysis based on countries and products.
Simple product counter Developer Profile
2 plugins · 40 total installs
How We Detect Simple product counter
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/simple-product-counter/css/fonts.css/wp-content/plugins/simple-product-counter/css/admin.css/wp-content/plugins/simple-product-counter/js/admin.js/wp-content/plugins/simple-product-counter/css/main.css/wp-content/plugins/simple-product-counter/js/admin.jssimple-product-counter/css/fonts.css?ver=simple-product-counter/css/admin.css?ver=simple-product-counter/js/admin.js?ver=simple-product-counter/css/main.css?ver=HTML / DOM Fingerprints
simple-product-counter-main-wrapperspc-settings-contspc-settings-cont-headerspc-settings-cont-mainspc-settings-titlespc-settings-type-contspc-settings-type-itmspc-saved-notification+4 moredata-target