Users Custom Posts Counts Security & Risk Analysis

wordpress.org/plugins/users-custom-posts-counts

Simple plugin that adds a new column showing custom type posts counts on the users list.

10 active installs v1.1 PHP + WP 3.0+ Updated Apr 13, 2016
classipresscustom-post-typesjobrollerpost-countuser-count
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Users Custom Posts Counts Safe to Use in 2026?

Generally Safe

Score 85/100

Users Custom Posts Counts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The "users-custom-posts-counts" plugin v1.1 presents a generally positive security posture based on the provided static analysis. The absence of any detected attack surface points like AJAX handlers, REST API routes, or shortcodes without proper authentication checks is a significant strength. Furthermore, the lack of any recorded vulnerabilities or CVEs in its history suggests a history of responsible development and maintenance.

However, there are areas for improvement that introduce minor risks. The code signals indicate a moderate concern regarding output escaping, with only 28% of outputs being properly escaped. This could potentially lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled carefully before being displayed. The presence of SQL queries that are not using prepared statements (only 29% are) also poses a risk of SQL injection, although the total number of SQL queries is relatively low.

While the plugin has a clean vulnerability history, the identified code signals warrant attention. The primary weaknesses lie in the less than ideal output escaping and the use of raw SQL queries. Addressing these areas would significantly enhance the plugin's security, moving it closer to an ideal state. Overall, the plugin is in a relatively good security state, but it is not entirely free of potential risks.

Key Concerns

  • Raw SQL queries present
  • Low percentage of properly escaped output
Vulnerabilities
None known

Users Custom Posts Counts Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Users Custom Posts Counts Code Analysis

Dangerous Functions
0
Raw SQL Queries
5
2 prepared
Unescaped Output
29
11 escaped
Nonce Checks
2
Capability Checks
1
File Operations
0
External Requests
2
Bundled Libraries
0

SQL Query Safety

29% prepared7 total queries

Output Escaping

28% escaped40 total outputs
Attack Surface

Users Custom Posts Counts Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 12
action_admin_menuadmin\about\AdminPage.php:60
actionadmin_initadmin\about\AdminPage.php:133
actionadmin_noticesadmin\about\AdminPage.php:134
actionadmin_menuadmin\about\AdminPage.php:137
filtercontextual_helpadmin\about\AdminPage.php:138
actionadmin_noticesadmin\about\AdminPage.php:246
actionadmin_enqueue_scriptsadmin\about\class-bc-about.php:123
filtermanage_users_custom_columnusers-custom-posts-count.php:17
filtermanage_users_columnsusers-custom-posts-count.php:18
actionadmin_menuusers-custom-posts-count.php:19
actionadmin_initusers-custom-posts-count.php:20
actionafter_setup_themeusers-custom-posts-count.php:21
Maintenance & Trust

Users Custom Posts Counts Maintenance & Trust

Maintenance Signals

WordPress version tested4.5.33
Last updatedApr 13, 2016
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Users Custom Posts Counts Developer Profile

SebeT

2 plugins · 810 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Users Custom Posts Counts

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/users-custom-posts-counts/admin/about/css/bc-about.css/wp-content/plugins/users-custom-posts-counts/admin/about/js/bc-about.js
Script Paths
/wp-content/plugins/users-custom-posts-counts/admin/about/js/bc-about.js
Version Parameters
users-custom-posts-counts/admin/about/css/bc-about.css?ver=users-custom-posts-counts/admin/about/js/bc-about.js?ver=

HTML / DOM Fingerprints

CSS Classes
bc-about-product-version
FAQ

Frequently Asked Questions about Users Custom Posts Counts