WHA Elementor Counter Up Security & Risk Analysis

wordpress.org/plugins/wha-elementor-counter-up

WHA Counter UP widget for Elementor allows you to add different animated widgets to the site. Easy to Install and Use.

30 active installs v1.0.0 PHP 5.5+ WP 4.0.1+ Updated Jul 27, 2020
animatedcountercountupcountupjselementor
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is WHA Elementor Counter Up Safe to Use in 2026?

Generally Safe

Score 85/100

WHA Elementor Counter Up has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The wha-elementor-counter-up plugin, version 1.0.0, exhibits a generally good security posture based on the provided static analysis. The absence of dangerous functions, SQL injection vulnerabilities (all queries use prepared statements), file operations, and external HTTP requests are strong positive indicators. The plugin also shows no known vulnerability history, which is a favorable sign for its reliability.

However, several areas raise concerns. A significant portion of output (42%) is not properly escaped, creating a potential for Cross-Site Scripting (XSS) vulnerabilities if any user-supplied data is rendered directly to the output. Furthermore, the complete lack of nonce checks and capability checks across all entry points (AJAX, REST API, shortcodes, cron) is a major security gap. This means any user, regardless of their role or permissions, could potentially trigger plugin functionalities, leading to unauthorized actions or information disclosure.

In conclusion, while the plugin avoids common pitfalls like raw SQL and dangerous functions, the unescaped output and, more critically, the absence of authorization and integrity checks present substantial risks. These weaknesses could be exploited to inject malicious scripts or perform unintended actions within the WordPress environment.

Key Concerns

  • Significant portion of output not properly escaped
  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
None known

WHA Elementor Counter Up Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WHA Elementor Counter Up Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
7 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

58% escaped12 total outputs
Attack Surface

WHA Elementor Counter Up Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionplugins_loadedinc\elementor\elementor.php:50
actionadmin_noticesinc\elementor\elementor.php:70
actionadmin_noticesinc\elementor\elementor.php:76
actionadmin_noticesinc\elementor\elementor.php:82
actionelementor/frontend/after_register_scriptsinc\elementor\plugin.php:83
actionelementor/elements/categories_registeredinc\elementor\plugin.php:86
actionelementor/widgets/widgets_registeredinc\elementor\plugin.php:89
Maintenance & Trust

WHA Elementor Counter Up Maintenance & Trust

Maintenance Signals

WordPress version tested5.4.19
Last updatedJul 27, 2020
PHP min version5.5
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs30
Developer Profile

WHA Elementor Counter Up Developer Profile

Web Help Agency

4 plugins · 270 total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WHA Elementor Counter Up

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wha-elementor-counter-up/assets/css/style.css/wp-content/plugins/wha-elementor-counter-up/assets/js/counter-up.js
Script Paths
/wp-content/plugins/wha-elementor-counter-up/assets/js/counter-up.js
Version Parameters
wha-elementor-counter-up/assets/css/style.css?ver=wha-elementor-counter-up/assets/js/counter-up.js?ver=

HTML / DOM Fingerprints

CSS Classes
wha-counter-up
Data Attributes
data-counter-enddata-counter-speeddata-counter-delay
FAQ

Frequently Asked Questions about WHA Elementor Counter Up