
WP Count Security & Risk Analysis
wordpress.org/plugins/wp-countTwo simple shortcodes to quickly display the total download count, in plain text, of any theme or plugin, using [theme-download-count slug="t …
Is WP Count Safe to Use in 2026?
Generally Safe
Score 100/100WP Count has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-count v0.1 plugin presents a mixed security posture. On the positive side, it demonstrates good practices by not exposing AJAX handlers or REST API routes without authentication and by exclusively using prepared statements for SQL queries. The absence of known CVEs and a clean vulnerability history also suggest a degree of diligence in its development and maintenance so far. However, significant concerns arise from the code analysis. The presence of the `unserialize` function without any apparent sanitization or context is a critical risk, potentially leading to Remote Code Execution if attacker-controlled data is processed. Furthermore, the complete lack of output escaping for all identified outputs is highly problematic, opening the door to Cross-Site Scripting (XSS) vulnerabilities, especially if the data being output originates from user input or external sources. The absence of nonce checks and capability checks on its entry points further exacerbates these risks by making it easier for unauthenticated or low-privileged users to trigger potential vulnerabilities. While the attack surface is currently small and all entry points appear to have some form of implicit protection, the insecure coding practices within the plugin itself are substantial weaknesses that need immediate attention.
Key Concerns
- Dangerous function unserialize used
- Output escaping is missing
- Nonce checks are missing
- Capability checks are missing
WP Count Security Vulnerabilities
WP Count Release Timeline
WP Count Code Analysis
Dangerous Functions Found
Output Escaping
WP Count Attack Surface
Shortcodes 2
WordPress Hooks 1
Maintenance & Trust
WP Count Maintenance & Trust
Maintenance Signals
Community Trust
WP Count Alternatives
StatCounter – Free Real Time Visitor Stats
official-statcounter-plugin-for-wordpress
StatCounter.com powered real-time detailed stats about the visitors to your blog.
Visitor Traffic Real Time Statistics
visitors-traffic-real-time-statistics
This plugin will help you to track your visitors, browsers, operating systems, visits and much more in one dashboard page.
Counter Number Showcase, Fun Facts – WordPress Animated Counter Plugin
counter-number-showcase
Counter Number WordPress Plugin brings you all the powerful Stats Counter features to your wordpress website
WPS Visitor Counter
wps-visitor-counter
Display website visitor statistics with widget, shortcode, and Gutenberg block support.
Mechanic Visitor Counter
mechanic-visitor-counter
Mechanic Visitor Counter is a widgets which will display the Visitor counter and traffic statistics on WordPress. Some of the features offered include …
WP Count Developer Profile
34 plugins · 52K total installs
How We Detect WP Count
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-count/HTML / DOM Fingerprints
[theme-download-count][plugin-download-count]