
Word Counter Security & Risk Analysis
wordpress.org/plugins/wordcounterShow the reading time and number of words in your post.
Is Word Counter Safe to Use in 2026?
Generally Safe
Score 85/100Word Counter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'wordcounter' plugin v1.0.0 exhibits an exceptionally strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the attack surface. Furthermore, the code analysis reveals no dangerous functions, no raw SQL queries, perfect output escaping, and no file operations or external HTTP requests. The lack of nonces, capability checks, and bundled libraries, while seemingly absent, contributes to a clean analysis report. The vulnerability history is also clear, with no known CVEs recorded. This indicates a plugin developed with robust security practices and a clean track record.
However, the complete absence of entry points (AJAX, REST API, shortcodes, cron) raises a question about the plugin's actual functionality and how users interact with it. While this is positive from a security perspective, it might mean the plugin offers minimal features or relies on an unusual integration method not captured by the analysis. The fact that there are no nonce checks, capability checks, or even any identified outputs or taint flows suggests either an extremely simple plugin or potential blind spots in the static analysis itself. The lack of these common security mechanisms could be a concern if the plugin were to evolve or handle user input in the future.
Overall, 'wordcounter' v1.0.0 presents as highly secure due to a minimal attack surface and clean code. Its vulnerability history is spotless, reinforcing this. The primary area for caution is the complete lack of common security checks, which, while currently not leading to identified vulnerabilities, means future development would require careful implementation of these checks. As it stands, the plugin is secure, but its limited observable functionality and absent standard security checks warrant a note of potential for future issues if expanded.
Word Counter Security Vulnerabilities
Word Counter Release Timeline
Word Counter Code Analysis
Word Counter Attack Surface
WordPress Hooks 8
Maintenance & Trust
Word Counter Maintenance & Trust
Maintenance Signals
Community Trust
Word Counter Alternatives
Just Writing Statistics
just-writing-statistics
Calculate your writing statistics on your WordPress site.
SJ Reading Time
sj-reading-time
SJ Reading Time helps you to quickly estimate your content read time and insert using a shortcode.
Reading Time WP
reading-time-wp
Reading Time WP creates an estimated reading time of your posts that is inserted above the content or by using a shortcode.
Surfer – WordPress Plugin
surferseo
Connect Surfer's Content Editor to WordPress. Write and optimize your articles for SEO, find new keyword ideas and publish straight to WordPress.
Novelist
novelist
Easily organize and display your portfolio of books.
Word Counter Developer Profile
1 plugin · 10 total installs
How We Detect Word Counter
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wordcounter/admin/css/wordcounter-admin.css/wp-content/plugins/wordcounter/admin/js/wordcounter-admin.js/wp-content/plugins/wordcounter/admin/js/wordcounter-admin.jswordcounter-admin.css?ver=wordcounter-admin.js?ver=HTML / DOM Fingerprints
wordcounter_options_form_submitid="wordcounter_options_form_submit"id="wordcounter_counter_position"id="wordcounter_counter_show_word_count"id="wordcounter_counter_show_reading_time"id="wordcounter_counter_show_powered_by"name="wordcounter_counter_position"+3 more