WP Post Visits Wizard Security & Risk Analysis

wordpress.org/plugins/wp-post-visits-wizard

WP Plugin to easily handle visits count on your posts and custom sorting based on this value

0 active installs v1.0.1 PHP 7.0+ WP 4.6+ Updated Apr 16, 2020
counterorderpostssortingvisits
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP Post Visits Wizard Safe to Use in 2026?

Generally Safe

Score 85/100

WP Post Visits Wizard has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

Based on the static analysis, "wp-post-visits-wizard" v1.0.1 exhibits a strong security posture with no identified attack surface points, dangerous functions, file operations, or external HTTP requests. The complete absence of raw SQL queries, coupled with the use of prepared statements for all database interactions, is a significant strength. However, the analysis also reveals a concerning lack of security measures, specifically zero nonce checks and zero capability checks. While there are no apparent taint flows or dangerous functions, the absence of these fundamental WordPress security checks means that any potential for code injection or unauthorized actions remains unmitigated. The plugin's vulnerability history is also clean, with no known CVEs, which is positive but could also be a reflection of its limited feature set and attack surface. Overall, the plugin demonstrates good practices in handling database queries but fails to implement essential security checks for user authentication and authorization, presenting a significant potential risk if new vulnerabilities are discovered or if its functionality evolves.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
  • Low output escaping coverage
Vulnerabilities
None known

WP Post Visits Wizard Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

WP Post Visits Wizard Release Timeline

v1.0.1Current
v1.0
Code Analysis
Analyzed Apr 16, 2026

WP Post Visits Wizard Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

33% escaped3 total outputs
Attack Surface

WP Post Visits Wizard Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionadmin_enqueue_scriptssrc/Bootstrap.php:44
actionadmin_menusrc/Bootstrap.php:46
actionwp-post-visits-wizard-appsrc/Bootstrap.php:48
actionwpsrc/Controller.php:33
filterthe_postssrc/Controller.php:34
actionwp_loadedsrc/Controller.php:35
actionadd_meta_boxessrc/Controller.php:36
actionrest_api_initsrc/Settings.php:35
Maintenance & Trust

WP Post Visits Wizard Maintenance & Trust

Maintenance Signals

WordPress version tested5.4.19
Last updatedApr 16, 2020
PHP min version7.0
Downloads968

Community Trust

Rating100/100
Number of ratings1
Active installs0
Developer Profile

WP Post Visits Wizard Developer Profile

Chris Baltazar

2 plugins · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP Post Visits Wizard

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-post-visits-wizard/src/assets/bootstrap-4.4.1.min.css/wp-content/plugins/wp-post-visits-wizard/src/assets/bootstrap-4.4.1.min.js/wp-content/plugins/wp-post-visits-wizard/src/assets/font-awesome-4.7.0.min.css/wp-content/plugins/wp-post-visits-wizard/src/assets/vue-dev.js/wp-content/plugins/wp-post-visits-wizard/src/assets/vue@2.6.11.js/wp-content/plugins/wp-post-visits-wizard/src/assets/vue-resource@1.5.1.js/wp-content/plugins/wp-post-visits-wizard/src/js/main.js
Script Paths
/wp-content/plugins/wp-post-visits-wizard/src/assets/bootstrap-4.4.1.min.js/wp-content/plugins/wp-post-visits-wizard/src/assets/font-awesome-4.7.0.min.css/wp-content/plugins/wp-post-visits-wizard/src/assets/vue-dev.js/wp-content/plugins/wp-post-visits-wizard/src/assets/vue@2.6.11.js/wp-content/plugins/wp-post-visits-wizard/src/assets/vue-resource@1.5.1.js/wp-content/plugins/wp-post-visits-wizard/src/js/main.js

HTML / DOM Fingerprints

JS Globals
pvwDatapvwEndpoint
REST Endpoints
/wp-json/wp-post-visits-wizard/save
FAQ

Frequently Asked Questions about WP Post Visits Wizard