
Word Count Analysis Security & Risk Analysis
wordpress.org/plugins/word-count-analysisA simple but useful plugin that gives the word count of your articles.
Is Word Count Analysis Safe to Use in 2026?
Generally Safe
Score 85/100Word Count Analysis has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "word-count-analysis" plugin, in version 1.0.11, exhibits a mixed security posture. While the absence of known CVEs and a lack of critical taint analysis findings are positive indicators, significant concerns arise from its static analysis results. The plugin possesses a single entry point via an AJAX handler that completely lacks authentication checks, presenting a direct pathway for unauthenticated attackers to interact with the plugin's functionality. Furthermore, the presence of multiple SQL queries (67% prepared) and a moderate rate of unescaped output (51%) suggest potential vulnerabilities if the unprotected AJAX handler can be leveraged to manipulate these areas. The plugin also bundles DataTables and Freemius v1.0, which, without further information on their specific versions, could represent a risk if outdated and vulnerable components are included.
Despite the lack of a historical vulnerability record, which might suggest a history of secure development or simply a lack of past scrutiny, the immediate static analysis findings paint a concerning picture. The unprotected AJAX handler is the most critical issue, as it bypasses WordPress's built-in security mechanisms. Combined with the less than ideal output escaping and the potential for even a small percentage of unsanitized SQL queries to be exploitable under certain conditions, this plugin warrants careful review and patching. The absence of nonce and capability checks on its sole entry point is a fundamental security oversight.
Key Concerns
- AJAX handler without authentication checks
- Low percentage of properly escaped output
- Bundled libraries (potential for outdated components)
- SQL queries not using prepared statements
Word Count Analysis Security Vulnerabilities
Word Count Analysis Release Timeline
Word Count Analysis Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Word Count Analysis Attack Surface
AJAX Handlers 1
WordPress Hooks 10
Maintenance & Trust
Word Count Analysis Maintenance & Trust
Maintenance Signals
Community Trust
Word Count Analysis Alternatives
Post Admin Word Count
post-admin-word-count
Adds a sortable word count column to the admin post list for all public post types. Efficient, lightweight and built with modern best practices.
Post word count in admin
post-word-count-in-admin
This plugin will help to count the number of words will show as new column at posts.
Post Word Counter and Thumbnail Checker
post-word-counter-and-thumbnail-checker
Simple Post Word Counter and Check which post has thumbnail or not.
WB Content Stats
wb-content-stats
A simple plugin to showcase the word & character count and reading time.
Reading Time WP
reading-time-wp
Reading Time WP creates an estimated reading time of your posts that is inserted above the content or by using a shortcode.
Word Count Analysis Developer Profile
2 plugins · 70 total installs
How We Detect Word Count Analysis
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/word-count-analysis/css/output.css/wp-content/plugins/word-count-analysis/js/wca_ajax.js/wp-content/plugins/word-count-analysis/js/wca_ajax.jsword-count-analysis/css/output.css?ver=word-count-analysis/js/wca_ajax.js?ver=HTML / DOM Fingerprints
wca_tab_dashboardwca_tab_authorswca_tab_postswca_tab_re_calculatewca_tab_prodata-wca-post-idajax_object