
Live Visitor Counter Security & Risk Analysis
wordpress.org/plugins/wp-visitors-widgetWordpress Live Visitor Counter allows you to display how many times a page has been viewed with this simple, fast and easy to use the plugin.
Is Live Visitor Counter Safe to Use in 2026?
Generally Safe
Score 85/100Live Visitor Counter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-visitors-widget" v2.2 plugin exhibits a mixed security posture. On the positive side, it has a very small attack surface with only one shortcode and no AJAX handlers, REST API routes, or cron events. Furthermore, there are no known vulnerabilities (CVEs) associated with this plugin, nor were any taint flows with unsanitized paths identified during static analysis. This suggests a generally well-maintained plugin with no immediately apparent critical security flaws. However, the code analysis reveals significant concerns regarding its secure coding practices. A substantial 16 SQL queries are present, none of which utilize prepared statements. This is a major risk, as it opens the door to SQL injection vulnerabilities if any user-supplied data is incorporated into these queries. Additionally, only 10% of output escaping is properly implemented, indicating a high likelihood of cross-site scripting (XSS) vulnerabilities. The complete absence of nonce and capability checks, even on the single shortcode entry point, further exacerbates these risks by allowing unauthorized actions or data manipulation. While the plugin's lack of historical vulnerabilities is a positive sign, the current code quality, particularly concerning SQL and output sanitization, presents considerable risks that outweigh this history.
Key Concerns
- SQL queries without prepared statements
- Low percentage of properly escaped output
- Missing nonce checks
- Missing capability checks
Live Visitor Counter Security Vulnerabilities
Live Visitor Counter Code Analysis
SQL Query Safety
Output Escaping
Live Visitor Counter Attack Surface
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
Live Visitor Counter Maintenance & Trust
Maintenance Signals
Community Trust
Live Visitor Counter Alternatives
Hostinger Reach – AI-Powered Email Marketing for WordPress
hostinger-reach
Launch and grow your email marketing effortlessly with Hostinger Reach. Collect contacts, sync subscribers, and send emails – all in one, AI powered.
Popup Builder & Popup Maker for WordPress – OptinMonster Email Marketing and Lead Generation
optinmonster
🤩 Make popups & optin forms to get more email newsletter subscribers, leads, and sales - #1 most popular popup builder plugin! 🚀
Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popups Builder
popup-maker
Want to boost sales & marketing efforts? Use your favorite forms & builder. Unlimited popups & impressions, keep your data, no monthly subscription.
MailPoet – Newsletters, Email Marketing, and Automation
mailpoet
Send beautiful newsletters from WordPress. Collect subscribers with signup forms, automate your emails for WooCommerce, blog post notifications & more
Creative Mail – Easier WordPress & WooCommerce Email Marketing
creative-mail-by-constant-contact
Creative Mail was designed specifically for WordPress and WooCommerce. Our intelligent (and super fun) email editor simplifies email marketing campaig …
Live Visitor Counter Developer Profile
1 plugin · 4K total installs
How We Detect Live Visitor Counter
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-visitors-widget/inc/assets/css/boot-cont.css/wp-content/plugins/wp-visitors-widget/css/admin.css/wp-content/plugins/wp-visitors-widget/css/front.css/wp-content/plugins/wp-visitors-widget/js/admin.js/wp-content/plugins/wp-visitors-widget/js/front.jswp-visitors-widget/inc/assets/css/boot-cont.css?ver=wp-visitors-widget/css/admin.css?ver=wp-visitors-widget/css/front.css?ver=wp-visitors-widget/js/admin.js?ver=wp-visitors-widget/js/front.js?ver=HTML / DOM Fingerprints
pulsing_overlap_smallpulsating-circleclass="random_prefix_val"window.wvw_local_data<input type="hidden" class="random_prefix_val" value=