
WPS Visitor Counter Security & Risk Analysis
wordpress.org/plugins/wps-visitor-counterDisplay website visitor statistics with widget, shortcode, and Gutenberg block support.
Is WPS Visitor Counter Safe to Use in 2026?
Mostly Safe
Score 78/100WPS Visitor Counter is generally safe to use. 1 past CVE were resolved.
The wps-visitor-counter plugin v1.4.9 exhibits a mixed security posture. On the positive side, the plugin demonstrates strong adherence to secure coding practices by exclusively using prepared statements for all SQL queries and implementing capability checks for its entry points. There are no detected dangerous functions, file operations, or external HTTP requests, which significantly reduces the potential for common web vulnerabilities. The output escaping is also generally good, with 83% of outputs properly escaped.
However, the static analysis reveals a critical taint flow with an unsanitized path, indicating a potential for high-severity vulnerabilities like cross-site scripting (XSS) or arbitrary file read/write, despite the absence of documented critical or high vulnerabilities in its history. The presence of one unpatched medium severity vulnerability from November 21, 2025, specifically an XSS, is a significant concern. While the vulnerability history shows only one medium CVE, the fact that it remains unpatched and the taint analysis identifying a critical issue warrants caution. This suggests that although the developers have implemented several security best practices, there might be overlooked vulnerabilities or inadequate sanitization in specific code paths.
In conclusion, while wps-visitor-counter has strengths in its use of prepared statements and capability checks, the identified critical taint flow and the unpatched medium XSS vulnerability represent notable weaknesses. These issues, coupled with the fact that there is only one documented CVE but a concerning taint analysis result, suggest that the plugin's security is not entirely robust and requires immediate attention to address the identified risks.
Key Concerns
- Unpatched CVE (Medium Severity)
- Critical severity taint flow with unsanitized path
- Output escaping (17% not properly escaped)
WPS Visitor Counter Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WPS Visitor Counter <= 1.4.8 - Reflected Cross-Site Scripting
WPS Visitor Counter Release Timeline
WPS Visitor Counter Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WPS Visitor Counter Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
WPS Visitor Counter Maintenance & Trust
Maintenance Signals
Community Trust
WPS Visitor Counter Alternatives
Mechanic Visitor Counter
mechanic-visitor-counter
Mechanic Visitor Counter is a widgets which will display the Visitor counter and traffic statistics on WordPress. Some of the features offered include …
XT Visitor Counter
xt-visitor-counter
XT Visitor Counter is a widgets which will display the Visitor counter and traffic statistics on WordPress. Some of the features offered include Today …
MC Visitor Tally
mc-visitor-tally
Displays unique daily visits. Web page tables. Dashboard widget with monthly comparisons.
Personal Hit Counter
personal-hit-counter
Inform the visitor, below the main content, how many times a specific Page, Post, or WooCommerce Product has been viewed by that visitor
Counter live visitors for WooCommerce
counter-visitor-for-woocommerce
Show user count on product
WPS Visitor Counter Developer Profile
3 plugins · 11K total installs
How We Detect WPS Visitor Counter
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wps-visitor-counter/styles/js/custom.js/wp-content/plugins/wps-visitor-counter/styles/css/default.css/wp-content/plugins/wps-visitor-counter/wps-gutenberg-block.js/wp-content/plugins/wps-visitor-counter/styles/js/custom.js/wp-content/plugins/wps-visitor-counter/wps-gutenberg-block.jswps-visitor-counter/styles/js/custom.js?ver=1.4.9wps-visitor-counter/styles/css/default.css?ver=1.4.9wps-visitor-counter/wps-gutenberg-block.js?ver=1.4.9HTML / DOM Fingerprints
wpsvc_plugins_wrapwpsvc_right_sidebarwpsvc_plugins_textwpsvc_option_wrap<!-- start mvc wrap --><!-- start right sidebar --><!-- Support Banner --><!----fastcomet----->+1 moredata-block="wps/wps-visitor-counter"wpspagevisit[wps_visitor_counter]