
Word Count Wizard Security & Risk Analysis
wordpress.org/plugins/word-count-wizardPlugin for bloggers who need detailed word count statistics of their blogs.
Is Word Count Wizard Safe to Use in 2026?
Generally Safe
Score 85/100Word Count Wizard has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "word-count-wizard" plugin v1.0.4 exhibits a generally positive security posture, with no known historical vulnerabilities (CVEs) and a clean taint analysis report, indicating no critical or high severity issues were detected in the analyzed code flows. The presence of nonce and capability checks on its single entry point (a shortcode) is a good practice for limiting unauthorized access. However, significant concerns arise from the static analysis of its code. A very low percentage of outputs (3%) are properly escaped, presenting a substantial risk of cross-site scripting (XSS) vulnerabilities. While the plugin has a limited attack surface and uses prepared statements for a majority of its SQL queries, the lack of output sanitization for most outputs is a critical oversight. The absence of bundled libraries is a positive, but the extensive unescaped output means the plugin's overall security is compromised despite its clean vulnerability history and basic authentication measures.
Key Concerns
- Low output escaping
- Unprotected entry points (though limited)
Word Count Wizard Security Vulnerabilities
Word Count Wizard Release Timeline
Word Count Wizard Code Analysis
SQL Query Safety
Output Escaping
Word Count Wizard Attack Surface
Shortcodes 1
WordPress Hooks 9
Maintenance & Trust
Word Count Wizard Maintenance & Trust
Maintenance Signals
Community Trust
Word Count Wizard Alternatives
No alternatives data available yet.
Word Count Wizard Developer Profile
1 plugin · 70 total installs
How We Detect Word Count Wizard
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/word-count-wizard/admin/css/wcwizard-admin.css/wp-content/plugins/word-count-wizard/admin/js/wcwizard-admin.js/wp-content/plugins/word-count-wizard/admin/js/wcwizard-admin.jswcwizard-admin.css?ver=wcwizard-admin.js?ver=HTML / DOM Fingerprints
wcwizard-admin-table<!-- wp-word-count-wizard -->data-wcwizard-idwcwizard_admin_params[word_count_wizard_stats]