Sortable Word Count Reloaded Security & Risk Analysis

wordpress.org/plugins/sortable-word-count-reloaded

Adds a sortable column to the posts and pages admin list with the word count of each page/post.

2K active installs v1.0.3 PHP 5.6+ WP 4.0.1+ Updated Jan 27, 2026
admincolumnpagespostsword-count
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Sortable Word Count Reloaded Safe to Use in 2026?

Generally Safe

Score 100/100

Sortable Word Count Reloaded has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The 'sortable-word-count-reloaded' plugin v1.0.3 exhibits a strong security posture based on the provided static analysis. The complete absence of attack surface vectors like AJAX handlers, REST API routes, shortcodes, and cron events significantly reduces the potential for external exploitation. Furthermore, the code's adherence to secure coding practices is evident in the lack of dangerous functions, file operations, and external HTTP requests. All SQL queries are prepared, and nonces and capability checks are present, indicating a foundational understanding of WordPress security. The vulnerability history being completely clear further reinforces its current security standing.

However, a critical concern arises from the output escaping signal. With one total output analyzed and 0% properly escaped, there is a clear risk of Cross-Site Scripting (XSS) vulnerabilities. Any user-generated or dynamically generated content outputted by the plugin without proper sanitization is susceptible to malicious code injection. While the plugin has no known vulnerabilities, this single unescaped output represents a significant potential weakness that attackers could exploit. The lack of taint analysis data is also noteworthy, though this could be due to the plugin's limited entry points.

Key Concerns

  • Unescaped output detected
Vulnerabilities
None known

Sortable Word Count Reloaded Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Sortable Word Count Reloaded Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped1 total outputs
Attack Surface

Sortable Word Count Reloaded Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actioninitsortable-word-count-reloaded.php:56
filtermanage_posts_columnssortable-word-count-reloaded.php:59
filtermanage_page_posts_columnssortable-word-count-reloaded.php:60
actionmanage_posts_custom_columnsortable-word-count-reloaded.php:63
actionmanage_page_posts_custom_columnsortable-word-count-reloaded.php:64
filtermanage_edit-post_sortable_columnssortable-word-count-reloaded.php:67
filtermanage_edit-page_sortable_columnssortable-word-count-reloaded.php:68
filterrequestsortable-word-count-reloaded.php:71
actionsave_postsortable-word-count-reloaded.php:74
actionadmin_headsortable-word-count-reloaded.php:77
actionplugins_loadedsortable-word-count-reloaded.php:218
Maintenance & Trust

Sortable Word Count Reloaded Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 27, 2026
PHP min version5.6
Downloads13K

Community Trust

Rating74/100
Number of ratings10
Active installs2K
Developer Profile

Sortable Word Count Reloaded Developer Profile

apasionados

28 plugins · 61K total installs

75
trust score
Avg Security Score
94/100
Avg Patch Time
326 days
View full developer profile
Detection Fingerprints

How We Detect Sortable Word Count Reloaded

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sortable-word-count-reloaded/style.css
Version Parameters
sortable-word-count-reloaded/style.css?ver=

HTML / DOM Fingerprints

CSS Classes
word_count
FAQ

Frequently Asked Questions about Sortable Word Count Reloaded