
WP-PostViews Security & Risk Analysis
wordpress.org/plugins/wp-postviewsEnables you to display how many times a post/page had been viewed.
Is WP-PostViews Safe to Use in 2026?
Generally Safe
Score 99/100WP-PostViews has a strong security track record. Known vulnerabilities have been patched promptly.
The "wp-postviews" plugin version 1.78 exhibits a mixed security posture. While it boasts a small attack surface with only 3 entry points and no unprotected AJAX handlers or REST API routes, it has significant concerns in its code implementation. A substantial portion of output is not properly escaped, potentially leading to cross-site scripting (XSS) vulnerabilities. Furthermore, the plugin uses raw SQL queries without prepared statements, which is a known vector for SQL injection attacks. The vulnerability history, though dated, reveals a past high-severity Cross-Site Request Forgery (CSRF) vulnerability, indicating that the plugin has had exploitable weaknesses in the past. While there are no current unpatched vulnerabilities and the taint analysis shows no immediate critical or high risks, the lack of proper output escaping and raw SQL queries are significant weaknesses that require attention to improve the plugin's overall security.
Key Concerns
- Raw SQL queries without prepared statements
- Low percentage of properly escaped output
- Historical high severity CVE (CSRF)
WP-PostViews Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WP-PostViews < 1.63 - Cross-Site Request Forgery
WP-PostViews Code Analysis
SQL Query Safety
Output Escaping
WP-PostViews Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 26
Maintenance & Trust
WP-PostViews Maintenance & Trust
Maintenance Signals
Community Trust
WP-PostViews Alternatives
Post Views Stats Counter
post-views-stats-counter
This plugin will display how many times post and page viewed. It shows total view of access per day, week, month, and all days.
WP-PostViews Plus
wp-postviews-plus
Enables You To Display How Many Times A Post Had Been Viewed By User Or Bot.
Easy Post View Counter
easy-post-view-counter
With this plugin you can see how many views a single post has.
WP-PostViews Plus widget
wp-postviews-plus-widget
This is a widget based on WP-PostViews Plus plugin by Richer Yang (http://wordpress.org/extend/plugins/wp-postviews-plus).
myCred for WP-PostViews
mycred-for-wp-postviews
📢🚨 Important Notice: myCred for WP-PostViews is now part of the myCred Toolkit and will no longer receive updates here. Only security fixes will be pr …
WP-PostViews Developer Profile
20 plugins · 889K total installs
How We Detect WP-PostViews
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-postviews/postviews-cache.js/wp-content/plugins/wp-postviews/postviews-cache.jswp-postviews/postviews-cache.js?ver=HTML / DOM Fingerprints
viewsCacheL10n%