
Wp User Count Security & Risk Analysis
wordpress.org/plugins/wp-user-countShow the current number of users in a line.
Is Wp User Count Safe to Use in 2026?
Generally Safe
Score 85/100Wp User Count has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'wp-user-count' plugin v0.2 exhibits a mixed security posture. On the positive side, the static analysis indicates a lack of known vulnerabilities in its history, no dangerous function usage, no file operations, no external HTTP requests, and all SQL queries are prepared. Furthermore, the attack surface appears minimal, with no AJAX handlers, REST API routes, shortcodes, or cron events exposed without authentication or permission checks, and the taint analysis shows no critical or high severity flows.
However, a significant concern arises from the complete lack of output escaping. With 11 outputs analyzed and 0% properly escaped, this presents a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. This means user-supplied data or data processed by the plugin could be injected into the output without sanitization, potentially allowing attackers to execute malicious scripts in users' browsers. Additionally, the absence of nonce checks and capability checks for any potential entry points, even though none were identified in this static analysis, suggests a reliance on the inherent security of the WordPress core rather than explicit plugin-level safeguards. While the vulnerability history is clean, the lack of output escaping is a glaring weakness that could be easily exploited.
Key Concerns
- No output escaping found
- No nonce checks
- No capability checks
Wp User Count Security Vulnerabilities
Wp User Count Release Timeline
Wp User Count Code Analysis
SQL Query Safety
Output Escaping
Wp User Count Attack Surface
WordPress Hooks 1
Maintenance & Trust
Wp User Count Maintenance & Trust
Maintenance Signals
Community Trust
Wp User Count Alternatives
Password Strength Settings for WooCommerce
wc-password-strength-settings
Help secure your WooCommerce site by enforcing stronger passwords and taking additional control of your strength requirements.
SysBasics Customize My Account for WooCommerce
customize-my-account-for-woocommerce
Optimize your WooCommerce My account page also add new endpoints and manage existing endpoints with ease.
Disable User Login
disable-user-login
Disable user accounts without deleting them. One-click enable/disable, bulk actions, force logout, and customizable disabled message.
User IP and Location
user-ip-and-location
Want to show your website visitors their IP address, location, and other cool details? This plugin makes it super easy! Now works perfectly with cachi …
Protect Admin
protect-admin-account
Protect admin accounts from being deleted or modified by other users. This plugin will always be hidden from all users other than the admin who instal …
Wp User Count Developer Profile
2 plugins · 20 total installs
How We Detect Wp User Count
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
wp-user-countid="WPusercount"name="WPusercount"id="wp-user-count"name="wp-user-count"