
Total Social Counter Security & Risk Analysis
wordpress.org/plugins/total-social-counterThis widget combines the number of your RSS readers, twitter followers, and fans of your facebook fan page.
Is Total Social Counter Safe to Use in 2026?
Generally Safe
Score 85/100Total Social Counter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'total-social-counter' plugin version 0.8.0 presents a mixed security posture. While it has no recorded vulnerabilities (CVEs) and its SQL queries are properly prepared, indicating good database practices, there are significant concerns regarding code quality and input validation. The presence of dangerous functions like 'unserialize' and 'create_function' is a red flag. 'unserialize' is notoriously prone to arbitrary code execution if it processes untrusted input, and 'create_function' is deprecated and generally considered unsafe. Furthermore, a low percentage of output is properly escaped (17%), suggesting a high risk of cross-site scripting (XSS) vulnerabilities where user-supplied data is displayed without adequate sanitization. The lack of capability checks and nonce checks on the identified entry points, while the attack surface is reported as zero, still leaves potential avenues for misuse if unforeseen entry points exist or if the zero count is inaccurate for this version.
The vulnerability history being clean is positive, suggesting a lack of historical exploitable flaws or proactive patching by developers. However, this does not negate the inherent risks identified in the static analysis. The absence of taint analysis flows with unsanitized paths is encouraging, but this could be due to the limited scope of the analysis or the specific nature of the plugin's functionality in this version. Overall, the plugin exhibits strengths in its SQL handling and lack of known CVEs, but the presence of dangerous functions and poor output escaping represent significant weaknesses that require immediate attention to improve its security.
Key Concerns
- Dangerous function: unserialize used
- Dangerous function: create_function used
- Low output escaping percentage (17%)
- No capability checks on entry points
- No nonce checks on entry points
Total Social Counter Security Vulnerabilities
Total Social Counter Code Analysis
Dangerous Functions Found
Output Escaping
Total Social Counter Attack Surface
WordPress Hooks 3
Maintenance & Trust
Total Social Counter Maintenance & Trust
Maintenance Signals
Community Trust
Total Social Counter Alternatives
Social Counter Widget
social-counter-widget
This widget will display your RSS subscribers, Twitter followers and Facebook fans in one nice looking box.
Metro Style Social Widget
metro-style-social-widget
Metro Style Social Network Widget
LH Posse
lh-posse
A flexible way to syndicate your content to Facebook, Twitter, or anywhere via IFTTT using customised feeds.
My Social Widgets With ShortCode
my-social-widgets-with-shortcode
Add social media widgets in the sidebar via widget or shortcode. Support Facebook, Twitter, Recent Posts. Fully Customizable
Subscribers Count
subscribers-count
Subscriber count show up the number of members of your community.
Total Social Counter Developer Profile
11 plugins · 2K total installs
How We Detect Total Social Counter
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/total-social-counter/css/total-social-counter.css/wp-content/plugins/total-social-counter/css/tipTip.css/wp-content/plugins/total-social-counter/js/jquery.tipTip.minified.js/wp-content/plugins/total-social-counter/js/script.jscss/total-social-counter.csscss/tipTip.cssjs/jquery.tipTip.minified.js/js/script.jstotal-social-counter/css/total-social-counter.css?ver=total-social-counter/css/tipTip.css?ver=total-social-counter/js/jquery.tipTip.minified.js?ver=total-social-counter/js/script.js?ver=HTML / DOM Fingerprints
total-social-counter-widget<!-- widget output --><!-- You can access the individual stats like this:$stats->twitter;$stats->facebook;+4 moreid="total_social_counter-title"name="total_social_counter-title"id="total_social_counter-twitter_id"name="total_social_counter-twitter_id"id="total_social_counter-facebook_id"name="total_social_counter-facebook_id"+2 morewindow.jQueryjQuery