
The Hits Counter Security & Risk Analysis
wordpress.org/plugins/the-hits-counterChecks and displays the number of hits for posts and pages
Is The Hits Counter Safe to Use in 2026?
Generally Safe
Score 100/100The Hits Counter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'the-hits-counter' v1.0 exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests is commendable. Importantly, all SQL queries utilize prepared statements, which mitigates the risk of SQL injection. However, there are some areas of concern. The plugin has a relatively low number of outputs, but a significant portion (33%) are not properly escaped, posing a potential risk of cross-site scripting (XSS) vulnerabilities if user-supplied data is reflected directly in the output. Additionally, the complete lack of nonce checks and capability checks across all entry points, including the single shortcode, is a notable weakness. While the attack surface is currently small, these missing authorization mechanisms mean that an attacker could potentially leverage the shortcode's functionality without proper validation, leading to unintended actions or information disclosure. The plugin's vulnerability history is clean, with no recorded CVEs, which suggests a history of good security practices or a lack of significant past vulnerabilities being discovered. Overall, the plugin is built on a solid foundation but requires attention to output escaping and robust authorization checks to reach a more secure state.
Key Concerns
- Missing nonce checks on entry points
- Missing capability checks on entry points
- Unescaped output detected
The Hits Counter Security Vulnerabilities
The Hits Counter Code Analysis
Output Escaping
The Hits Counter Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
The Hits Counter Maintenance & Trust
Maintenance Signals
Community Trust
The Hits Counter Alternatives
WP-PostViews
wp-postviews
Enables you to display how many times a post/page had been viewed.
Visitor Traffic Real Time Statistics
visitors-traffic-real-time-statistics
This plugin will help you to track your visitors, browsers, operating systems, visits and much more in one dashboard page.
SRS Simple Hits Counter
srs-simple-hits-counter
Simple plugin to count and show a total number of hits (Unique visitors or page-views) to the site without using any third party code.
WP Post Statistics (Visitors & Visits Counter)
wp-post-real-time-statistics
a simple tool to know your post statistics
Counter-Hits
counter-hits
A simple, easy, fast, adaptive, local, objective counter to visit your site.
The Hits Counter Developer Profile
8 plugins · 65K total installs
How We Detect The Hits Counter
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
hits-counter[thc_hits_count]