View Post counter Security & Risk Analysis

wordpress.org/plugins/view-post-counter

This is very simple plugin of view post counter

90 active installs v1.1 PHP + WP 3.0+ Updated Jul 3, 2015
counterhitspostpost-viewsview
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is View Post counter Safe to Use in 2026?

Generally Safe

Score 85/100

View Post counter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The static analysis of the "view-post-counter" plugin v1.1 reveals a seemingly secure codebase, with no detected dangerous functions, SQL injection vulnerabilities, or file operations. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface. However, a critical concern arises from the output escaping, where 100% of outputs are not properly escaped. This indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the WordPress site through the plugin's output.

The vulnerability history shows no recorded CVEs, which is a positive indicator. This suggests that the plugin has historically been developed with security in mind or that it has not attracted significant security research. However, the lack of historical vulnerabilities does not negate the immediate risks identified in the static analysis.

In conclusion, while the plugin exhibits strengths in its limited attack surface and secure database interaction practices, the complete lack of output escaping poses a substantial XSS risk. This weakness must be addressed promptly to ensure the security of any WordPress site using this plugin.

Key Concerns

  • Unescaped output detected
Vulnerabilities
None known

View Post counter Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

View Post counter Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped1 total outputs
Attack Surface

View Post counter Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
filtermanage_posts_columnsview-post-counter.php:79
actionmanage_posts_custom_columnview-post-counter.php:85
Maintenance & Trust

View Post counter Maintenance & Trust

Maintenance Signals

WordPress version tested3.5.2
Last updatedJul 3, 2015
PHP min version
Downloads8K

Community Trust

Rating96/100
Number of ratings4
Active installs90
Developer Profile

View Post counter Developer Profile

ThemesVila

14 plugins · 2K total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect View Post counter

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about View Post counter