
Taxonomy Terms Counter Security & Risk Analysis
wordpress.org/plugins/taxonomy-terms-counterShow taxonomy term counts in the Gutenberg editor sidebar and manage which taxonomies display counts.
Is Taxonomy Terms Counter Safe to Use in 2026?
Generally Safe
Score 100/100Taxonomy Terms Counter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "taxonomy-terms-counter" v1.0.0 plugin exhibits a strong security posture based on the provided static analysis and vulnerability history. All identified entry points (REST API routes) include permission callbacks, indicating proper authorization checks. The use of prepared statements for all SQL queries is a significant strength, preventing SQL injection vulnerabilities. Additionally, the absence of dangerous functions, file operations, and external HTTP requests further reduces the attack surface.
However, there are a few areas that could be improved. While the majority of output is properly escaped, the 20% that is not could potentially lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is present in those unescaped outputs. The lack of nonce checks on AJAX handlers is also a concern, as it leaves these endpoints open to cross-site request forgery (CSRF) attacks. The plugin's vulnerability history shows no known CVEs, which is excellent, but it also means there's limited historical data to assess long-term security trends.
In conclusion, "taxonomy-terms-counter" v1.0.0 is a relatively secure plugin, with its strengths lying in its secure handling of SQL queries and its well-defined REST API endpoints. The primary areas for improvement involve ensuring all output is properly escaped and implementing nonce checks for AJAX handlers to further harden the plugin against common web vulnerabilities. The lack of any historical vulnerabilities is a positive indicator, but continued vigilance in code review and security practices is always recommended.
Key Concerns
- Unescaped output detected
- Missing nonce checks on AJAX
Taxonomy Terms Counter Security Vulnerabilities
Taxonomy Terms Counter Code Analysis
Output Escaping
Taxonomy Terms Counter Attack Surface
REST API Routes 3
WordPress Hooks 6
Maintenance & Trust
Taxonomy Terms Counter Maintenance & Trust
Maintenance Signals
Community Trust
Taxonomy Terms Counter Alternatives
Classic Editor
classic-editor
Enables the previous "classic" editor and the old-style Edit Post screen with TinyMCE, Meta Boxes, etc. Supports all plugins that extend this screen.
Starter Templates – AI-Powered Templates for Elementor & Gutenberg
astra-sites
The growing library of 300+ ready-to-use templates that work with all WordPress themes including Astra, Hello, OceanWP, GeneratePress and more
Classic Widgets
classic-widgets
Enables the previous "classic" widgets settings screens in Appearance - Widgets and the Customizer. Disables the block editor from managing widgets.
Advanced Editor Tools
tinymce-advanced
Extends and enhances the block editor (Gutenberg) and the classic editor (TinyMCE).
Spectra Gutenberg Blocks – Website Builder for the Block Editor
ultimate-addons-for-gutenberg
Power-up Gutenberg with advanced blocks for faster website creation. Build your WordPress website effortlessly using powerful building blocks!
Taxonomy Terms Counter Developer Profile
1 plugin · 0 total installs
How We Detect Taxonomy Terms Counter
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/taxonomy-terms-counter/assets/build/admin.js/wp-content/plugins/taxonomy-terms-counter/assets/build/admin.css/wp-content/plugins/taxonomy-terms-counter/assets/build/taxonomy-terms-counter.js/wp-content/plugins/taxonomy-terms-counter/assets/build/admin.js/wp-content/plugins/taxonomy-terms-counter/assets/build/taxonomy-terms-counter.jstaxonomy-terms-counter/assets/build/admin.js?ver=1.0.0taxonomy-terms-counter/assets/build/taxonomy-terms-counter.js?ver=1.0.0taxonomy-terms-counter/assets/build/admin.css?ver=1.0.0HTML / DOM Fingerprints
ttcounter-admin-rootTTCounter/wp-json/ttcounter/v1/settings