
Subscribers Count Security & Risk Analysis
wordpress.org/plugins/subscribers-countSubscriber count show up the number of members of your community.
Is Subscribers Count Safe to Use in 2026?
Generally Safe
Score 85/100Subscribers Count has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "subscribers-count" v1.0 plugin exhibits a mixed security posture, with some commendable practices alongside significant areas of concern. On the positive side, the plugin has no recorded vulnerabilities (CVEs), no bundled libraries, and demonstrates a commitment to secure database interaction by using prepared statements for all SQL queries. The attack surface also appears to be zero, which is excellent from an entry point perspective.
However, the static analysis reveals critical weaknesses. A striking 100% of output is unescaped, posing a significant risk of Cross-Site Scripting (XSS) vulnerabilities. The taint analysis indicates flows with unsanitized paths, suggesting potential for code injection or other vulnerabilities, even if currently assessed as low severity. Furthermore, the complete lack of nonce checks and capability checks on the (albeit non-existent) entry points is a major oversight. While the attack surface is reported as zero, the presence of file operations and external HTTP requests without clear authentication or sanitization could still be exploited if an attacker can influence the input to these functions.
The vulnerability history being completely clean is a positive indicator, but it does not negate the risks identified in the static analysis. The lack of past vulnerabilities might be due to the plugin's limited functionality or a lack of targeted analysis in the past. The plugin's strengths lie in its clean record and SQL hygiene, but the severe lack of output escaping and potential for unsanitized input flows demand immediate attention to mitigate significant security risks.
Key Concerns
- All output is unescaped
- Taint flows with unsanitized paths
- No nonce checks
- No capability checks
Subscribers Count Security Vulnerabilities
Subscribers Count Code Analysis
Output Escaping
Data Flow Analysis
Subscribers Count Attack Surface
WordPress Hooks 5
Maintenance & Trust
Subscribers Count Maintenance & Trust
Maintenance Signals
Community Trust
Subscribers Count Alternatives
Social Counter Widget
social-counter-widget
This widget will display your RSS subscribers, Twitter followers and Facebook fans in one nice looking box.
Total Social Counter
total-social-counter
This widget combines the number of your RSS readers, twitter followers, and fans of your facebook fan page.
Social Counters
social-counters
It allows to place counters and social sharing links to the most popular social networks like Menéame, Twitter, Facebook, Google Buzz, Tuenti or Bitac …
LH Posse
lh-posse
A flexible way to syndicate your content to Facebook, Twitter, or anywhere via IFTTT using customised feeds.
Word Count and Social Shares
word-count-and-social-shares
This Wordpress plugin will work as part of wp-admin and report on correlation between word count and social shares.
Subscribers Count Developer Profile
1 plugin · 10 total installs
How We Detect Subscribers Count
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/subscribers-count/css/styles.cssHTML / DOM Fingerprints
wrapplaceholder_gaq