Word Counter Security & Risk Analysis

wordpress.org/plugins/wordcounter

Show the reading time and number of words in your post.

10 active installs v1.0.0 PHP 7.0+ WP 3.0.1+ Updated Jan 8, 2024
authorsreading-timeword-countwordswriting
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Word Counter Safe to Use in 2026?

Generally Safe

Score 85/100

Word Counter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The 'wordcounter' plugin v1.0.0 exhibits an exceptionally strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the attack surface. Furthermore, the code analysis reveals no dangerous functions, no raw SQL queries, perfect output escaping, and no file operations or external HTTP requests. The lack of nonces, capability checks, and bundled libraries, while seemingly absent, contributes to a clean analysis report. The vulnerability history is also clear, with no known CVEs recorded. This indicates a plugin developed with robust security practices and a clean track record.

However, the complete absence of entry points (AJAX, REST API, shortcodes, cron) raises a question about the plugin's actual functionality and how users interact with it. While this is positive from a security perspective, it might mean the plugin offers minimal features or relies on an unusual integration method not captured by the analysis. The fact that there are no nonce checks, capability checks, or even any identified outputs or taint flows suggests either an extremely simple plugin or potential blind spots in the static analysis itself. The lack of these common security mechanisms could be a concern if the plugin were to evolve or handle user input in the future.

Overall, 'wordcounter' v1.0.0 presents as highly secure due to a minimal attack surface and clean code. Its vulnerability history is spotless, reinforcing this. The primary area for caution is the complete lack of common security checks, which, while currently not leading to identified vulnerabilities, means future development would require careful implementation of these checks. As it stands, the plugin is secure, but its limited observable functionality and absent standard security checks warrant a note of potential for future issues if expanded.

Vulnerabilities
None known

Word Counter Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Word Counter Release Timeline

v1.0.0Current
Code Analysis
Analyzed Apr 16, 2026

Word Counter Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Word Counter Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionadmin_initadmin/class-wordcounter-admin.php:55
actionadmin_menuadmin/class-wordcounter-admin.php:56
actionplugins_loadedincludes/class-wordcounter.php:146
actionadmin_enqueue_scriptsincludes/class-wordcounter.php:161
actionadmin_enqueue_scriptsincludes/class-wordcounter.php:162
actionwp_enqueue_scriptsincludes/class-wordcounter.php:177
actionwp_enqueue_scriptsincludes/class-wordcounter.php:178
filterthe_contentincludes/class-wordcounter.php:179
Maintenance & Trust

Word Counter Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedJan 8, 2024
PHP min version7.0
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Word Counter Developer Profile

nearchx

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Word Counter

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wordcounter/admin/css/wordcounter-admin.css/wp-content/plugins/wordcounter/admin/js/wordcounter-admin.js
Script Paths
/wp-content/plugins/wordcounter/admin/js/wordcounter-admin.js
Version Parameters
wordcounter-admin.css?ver=wordcounter-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
wordcounter_options_form_submit
Data Attributes
id="wordcounter_options_form_submit"id="wordcounter_counter_position"id="wordcounter_counter_show_word_count"id="wordcounter_counter_show_reading_time"id="wordcounter_counter_show_powered_by"name="wordcounter_counter_position"+3 more
FAQ

Frequently Asked Questions about Word Counter