
WHA Elementor Counter Up Security & Risk Analysis
wordpress.org/plugins/wha-elementor-counter-upWHA Counter UP widget for Elementor allows you to add different animated widgets to the site. Easy to Install and Use.
Is WHA Elementor Counter Up Safe to Use in 2026?
Generally Safe
Score 85/100WHA Elementor Counter Up has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wha-elementor-counter-up plugin, version 1.0.0, exhibits a generally good security posture based on the provided static analysis. The absence of dangerous functions, SQL injection vulnerabilities (all queries use prepared statements), file operations, and external HTTP requests are strong positive indicators. The plugin also shows no known vulnerability history, which is a favorable sign for its reliability.
However, several areas raise concerns. A significant portion of output (42%) is not properly escaped, creating a potential for Cross-Site Scripting (XSS) vulnerabilities if any user-supplied data is rendered directly to the output. Furthermore, the complete lack of nonce checks and capability checks across all entry points (AJAX, REST API, shortcodes, cron) is a major security gap. This means any user, regardless of their role or permissions, could potentially trigger plugin functionalities, leading to unauthorized actions or information disclosure.
In conclusion, while the plugin avoids common pitfalls like raw SQL and dangerous functions, the unescaped output and, more critically, the absence of authorization and integrity checks present substantial risks. These weaknesses could be exploited to inject malicious scripts or perform unintended actions within the WordPress environment.
Key Concerns
- Significant portion of output not properly escaped
- No nonce checks on entry points
- No capability checks on entry points
WHA Elementor Counter Up Security Vulnerabilities
WHA Elementor Counter Up Code Analysis
Output Escaping
WHA Elementor Counter Up Attack Surface
WordPress Hooks 7
Maintenance & Trust
WHA Elementor Counter Up Maintenance & Trust
Maintenance Signals
Community Trust
WHA Elementor Counter Up Alternatives
WP CountUP JS
wp-countup-js
Display multiple animated counters into your WordPress site.
Counter Number Showcase, Fun Facts – WordPress Animated Counter Plugin
counter-number-showcase
Counter Number WordPress Plugin brings you all the powerful Stats Counter features to your wordpress website
Uji Countdown
uji-countdown
A fully-customizable HTML5 countdown timer with Block Editor support.
Counters Block – Animated Number Counters for Stats and Goals
counters-block
A great way to display numbers in a fun and interesting way.
Themeflection Numbers – Number Counter and Animated Numbers
tf-numbers-number-counter-animaton
Very easy to use numbers counter. It will ultimately supply you with beautiful sections with counting numbers. You can use it to display statistics, o …
WHA Elementor Counter Up Developer Profile
4 plugins · 270 total installs
How We Detect WHA Elementor Counter Up
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wha-elementor-counter-up/assets/css/style.css/wp-content/plugins/wha-elementor-counter-up/assets/js/counter-up.js/wp-content/plugins/wha-elementor-counter-up/assets/js/counter-up.jswha-elementor-counter-up/assets/css/style.css?ver=wha-elementor-counter-up/assets/js/counter-up.js?ver=HTML / DOM Fingerprints
wha-counter-updata-counter-enddata-counter-speeddata-counter-delay