
WP Views Counter Security & Risk Analysis
wordpress.org/plugins/wpecounterFast, lightweight post views counter. Display views in admin, blocks or shortcodes — no tracking scripts required.
Is WP Views Counter Safe to Use in 2026?
Generally Safe
Score 98/100WP Views Counter has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The wpecounter v2.1.3 plugin exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by utilizing prepared statements for all SQL queries and implementing nonce and capability checks for its entry points. The static analysis revealed no critical or high-severity taint flows, and there are no file operations or external HTTP requests, which reduces the attack surface. However, a significant concern arises from the output escaping. With only 64% of outputs properly escaped, there is a notable risk of Cross-Site Scripting (XSS) vulnerabilities. This is further underscored by the plugin's vulnerability history, which includes two medium-severity CVEs, with common types being Missing Authorization and Improper Neutralization of Input During Web Page Generation (XSS). Although there are no currently unpatched vulnerabilities, the historical pattern of XSS suggests that output escaping remains a weak point that attackers could potentially exploit.
Key Concerns
- Insufficient output escaping
- Medium severity historical CVEs
WP Views Counter Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Views Counter <= 2.1.2 - Missing Authorization
WP Views Counter <= 2.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
WP Views Counter Release Timeline
WP Views Counter Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Views Counter Attack Surface
AJAX Handlers 3
Shortcodes 2
WordPress Hooks 22
Maintenance & Trust
WP Views Counter Maintenance & Trust
Maintenance Signals
Community Trust
WP Views Counter Alternatives
WebberZone Top 10 — Popular Posts
top-10
Track post views and page views, and display popular posts and trending content on your WordPress site.
Statify Widget
statify-widget
Data privacy conform widget for list popular content (pages, posts, custom post types) – based on Statify plugin.
Trending/Popular Post Slider and Widget
wp-trending-post-slider-and-widget
A quick, easy way to add Popular/Trending posts slider, grid block and widget. Also work with Gutenberg shortcode block.
Toplytics
toplytics
Displays the most visited posts as a widget using data from Google Analytics. Designed to be used under high-traffic or low server resources.
PostViews Count & Popular Posts Widgets
tp-postviews-count-popular-posts-widgets
TP WordPress Post Views Counter and Popular Posts Widget based on Post Views Plugin (TP WP Post Views) will help sites to add post views and show Popu …
WP Views Counter Developer Profile
12 plugins · 13K total installs
How We Detect WP Views Counter
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wpecounter/assets/css/wpecounter-admin.css/wp-content/plugins/wpecounter/assets/css/wpecounter.css/wp-content/plugins/wpecounter/assets/js/wpecounter-admin.js/wp-content/plugins/wpecounter/assets/js/wpecounter.js/wp-content/plugins/wpecounter/assets/js/wpecounter.js/wp-content/plugins/wpecounter/assets/js/wpecounter-admin.jswpecounter/assets/css/wpecounter-admin.css?ver=wpecounter/assets/css/wpecounter.css?ver=wpecounter/assets/js/wpecounter-admin.js?ver=wpecounter/assets/js/wpecounter.js?ver=HTML / DOM Fingerprints
wpecounter-reset-views-btnwpecounter-views-boxwpecounter-views-labeldata-postiddata-nonceWPeCounter_Settingswpecounter_object[wpecounter][WPeCounter]