
Views Counter – Pages/Posts Security & Risk Analysis
wordpress.org/plugins/views-counterSimple Plugin for showing the post or page view on Admin Column.no need to add code to theme file.just activate the plugin and enjoy.
Is Views Counter – Pages/Posts Safe to Use in 2026?
Generally Safe
Score 85/100Views Counter – Pages/Posts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "views-counter" plugin version 1.0 exhibits a generally strong security posture based on the provided static analysis. The absence of identified AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the potential attack surface. Furthermore, the code signals show a positive absence of dangerous functions, file operations, and external HTTP requests. Crucially, all SQL queries are properly prepared, and there are no recorded vulnerabilities or CVEs for this plugin. This indicates a well-developed and secure plugin in its current version.
However, a significant concern arises from the output escaping analysis. With one total output and 0% properly escaped, there is a high likelihood of cross-site scripting (XSS) vulnerabilities. Any data displayed to users that originates from user input or is not properly sanitized before output could be exploited. The lack of nonce and capability checks, while not directly identified as exploitable given the limited attack surface, is a missed opportunity for robust security and could become a concern if the plugin's functionality expands in the future. The absence of taint analysis results is also notable, though this may simply mean no concerning flows were detected or the analysis was limited.
In conclusion, while the plugin benefits from a minimal attack surface and good practices in areas like SQL handling and vulnerability history, the critical flaw in output escaping presents a substantial risk. This needs to be addressed immediately to prevent potential XSS attacks. The lack of checks, while not currently a direct vulnerability, suggests a need for more defensive programming practices as the plugin evolves.
Key Concerns
- Output escaping is not implemented
Views Counter – Pages/Posts Security Vulnerabilities
Views Counter – Pages/Posts Code Analysis
Output Escaping
Views Counter – Pages/Posts Attack Surface
WordPress Hooks 5
Maintenance & Trust
Views Counter – Pages/Posts Maintenance & Trust
Maintenance Signals
Community Trust
Views Counter – Pages/Posts Alternatives
Easy Post View Counter
easy-post-view-counter
With this plugin you can see how many views a single post has.
Post Views Stats Counter
post-views-stats-counter
This plugin will display how many times post and page viewed. It shows total view of access per day, week, month, and all days.
View Post counter
view-post-counter
This is very simple plugin of view post counter
DP Post Views Counter
dp-post-views
The plugin show how many people have viewed an article on the site.
Simple Post View Counter – Clean and Fast Post View Analytics
simple-post-view-counter
Lightweight post view counter with a widget and shortcodes. Track post views automatically, stop double-counting, and display popular content easily.
Views Counter – Pages/Posts Developer Profile
10 plugins · 7K total installs
How We Detect Views Counter – Pages/Posts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.