World Population Counter Security & Risk Analysis

wordpress.org/plugins/world-population-counter

Adds live world population counter to your site.

70 active installs v1.4.1 PHP + WP 4.4+ Updated Sep 4, 2025
clockcounterpopulationworld
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is World Population Counter Safe to Use in 2026?

Generally Safe

Score 100/100

World Population Counter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8mo ago
Risk Assessment

The "world-population-counter" plugin version 1.4.1 presents a mixed security posture. On the positive side, the plugin demonstrates good practices regarding SQL queries, exclusively using prepared statements, and has no recorded vulnerability history (CVEs). This suggests a potentially stable codebase with limited past security incidents. However, significant concerns arise from the static analysis. The plugin exposes two AJAX handlers without any authentication checks, creating a substantial attack surface for unauthorized actions. Furthermore, a notable percentage of its output (41%) is not properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is processed and displayed without adequate sanitization. The lack of any recorded taint flows might be misleading if the taint analysis was incomplete or if the plugin's complexity is low.

Key Concerns

  • Unprotected AJAX handlers
  • Insufficient output escaping
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

World Population Counter Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

World Population Counter Release Timeline

v1.4.1Current
v1.4.0
v1.3.1
v1.3.0
v1.2.0
v1.1.1
v1.1.0
v1.0.0
Code Analysis
Analyzed Mar 16, 2026

World Population Counter Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
11
16 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

59% escaped27 total outputs
Attack Surface
2 unprotected

World Population Counter Attack Surface

Entry Points3
Unprotected2

AJAX Handlers 2

authwp_ajax_alg_population_counterincludes\class-alg-world-population-counter.php:71
noprivwp_ajax_alg_population_counterincludes\class-alg-world-population-counter.php:72

Shortcodes 1

[alg_world_population_counter] includes\class-alg-world-population-counter.php:75
WordPress Hooks 6
actionadmin_menuincludes\admin\class-alg-settings-world-population-counter.php:35
actionadmin_initincludes\admin\class-alg-settings-world-population-counter.php:36
actioninitincludes\class-alg-world-population-counter.php:60
actionwp_enqueue_scriptsincludes\class-alg-world-population-counter.php:68
actionwidgets_initincludes\class-alg-world-population-counter.php:79
actionplugins_loadedworld-population-counter.php:35
Maintenance & Trust

World Population Counter Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 4, 2025
PHP min version
Downloads6K

Community Trust

Rating100/100
Number of ratings1
Active installs70
Developer Profile

World Population Counter Developer Profile

WPFactory

64 plugins · 137K total installs

77
trust score
Avg Security Score
97/100
Avg Patch Time
94 days
View full developer profile
Detection Fingerprints

How We Detect World Population Counter

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/world-population-counter/includes/js/number-format.js/wp-content/plugins/world-population-counter/includes/js/counter-ajax.js/wp-content/plugins/world-population-counter/includes/js/counter-simple.js
Script Paths
/wp-content/plugins/world-population-counter/includes/js/number-format.js/wp-content/plugins/world-population-counter/includes/js/counter-ajax.js/wp-content/plugins/world-population-counter/includes/js/counter-simple.js
Version Parameters
world-population-counter/includes/js/number-format.js?ver=world-population-counter/includes/js/counter-ajax.js?ver=world-population-counter/includes/js/counter-simple.js?ver=

HTML / DOM Fingerprints

JS Globals
alg_data_counter
Shortcode Output
[alg_world_population_counter]
FAQ

Frequently Asked Questions about World Population Counter