
WP Visit Counter Security & Risk Analysis
wordpress.org/plugins/wp-visit-counterSimply displays one more column in your posts/pages for number of visits.
Is WP Visit Counter Safe to Use in 2026?
Generally Safe
Score 85/100WP Visit Counter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-visit-counter" v1.0 plugin exhibits a mixed security posture. On the positive side, the plugin has no recorded vulnerabilities (CVEs) and a relatively small attack surface consisting of a single shortcode. It also avoids dangerous functions, file operations, and external HTTP requests, which are common vectors for exploitation. However, significant concerns arise from the static analysis. A concerning 100% of the single output identified is not properly escaped, posing a risk of Cross-Site Scripting (XSS) vulnerabilities. Furthermore, a critical taint flow with an unsanitized path was detected, indicating a potential for path traversal or arbitrary file access if this flow is exploited in conjunction with user-supplied input. The absence of nonce checks and capability checks on entry points is also a notable weakness, leaving the plugin susceptible to CSRF attacks and unauthorized actions if the shortcode's functionality can be manipulated.
Key Concerns
- Unescaped output detected
- Taint flow with unsanitized path (critical)
- Missing nonce checks
- Missing capability checks
WP Visit Counter Security Vulnerabilities
WP Visit Counter Release Timeline
WP Visit Counter Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Visit Counter Attack Surface
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
WP Visit Counter Maintenance & Trust
Maintenance Signals
Community Trust
WP Visit Counter Alternatives
No alternatives data available yet.
WP Visit Counter Developer Profile
2 plugins · 20 total installs
How We Detect WP Visit Counter
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
wp_vistcnt_get_the_user_ipshow_ip