
XT Visitor Counter Security & Risk Analysis
wordpress.org/plugins/xt-visitor-counterXT Visitor Counter is a widgets which will display the Visitor counter and traffic statistics on WordPress. Some of the features offered include Today …
Is XT Visitor Counter Safe to Use in 2026?
Generally Safe
Score 85/100XT Visitor Counter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "xt-visitor-counter" v1.4.3 presents a mixed security posture. On the positive side, it has a very small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events that are accessible externally. Furthermore, there are no known vulnerabilities (CVEs) associated with this plugin, and the vulnerability history is clean, suggesting a generally well-maintained codebase. However, significant concerns arise from the static analysis. The plugin exhibits a critical weakness in output escaping, with 0% of its outputs being properly escaped. This means that any data displayed by the plugin is vulnerable to cross-site scripting (XSS) attacks. Additionally, while the number of SQL queries is moderate, half of them do not use prepared statements, which can lead to SQL injection vulnerabilities. The presence of two unsanitized path flows in the taint analysis, though not classified as critical or high severity, indicates potential for file inclusion or directory traversal vulnerabilities if these flows are exploited. The lack of nonce checks and limited capability checks also contribute to potential security gaps, especially if any of the internal operations were to become exposed.
Key Concerns
- 0% proper output escaping
- 50% SQL queries not prepared
- 2 unsanitized path flows (taint analysis)
- No nonce checks
- Only 1 capability check
XT Visitor Counter Security Vulnerabilities
XT Visitor Counter Release Timeline
XT Visitor Counter Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
XT Visitor Counter Attack Surface
WordPress Hooks 3
Maintenance & Trust
XT Visitor Counter Maintenance & Trust
Maintenance Signals
Community Trust
XT Visitor Counter Alternatives
Mechanic Visitor Counter
mechanic-visitor-counter
Mechanic Visitor Counter is a widgets which will display the Visitor counter and traffic statistics on WordPress. Some of the features offered include …
WPS Visitor Counter
wps-visitor-counter
Display website visitor statistics with widget, shortcode, and Gutenberg block support.
MC Visitor Tally
mc-visitor-tally
Displays unique daily visits. Web page tables. Dashboard widget with monthly comparisons.
Counter live visitors for WooCommerce
counter-visitor-for-woocommerce
Show user count on product
Live Visitor Counter
wp-visitors-widget
Wordpress Live Visitor Counter allows you to display how many times a page has been viewed with this simple, fast and easy to use the plugin.
XT Visitor Counter Developer Profile
2 plugins · 7K total installs
How We Detect XT Visitor Counter
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/xt-visitor-counter/css/xt-visitor-counter-style.css/wp-content/plugins/xt-visitor-counter/js/xt-visitor-counter-script.js/wp-content/plugins/xt-visitor-counter/js/xt-visitor-counter-script.jsxt-visitor-counter/css/xt-visitor-counter-style.css?ver=xt-visitor-counter/js/xt-visitor-counter-script.js?ver=HTML / DOM Fingerprints
xtvc_plugins_wrapxtvc_right_sidebarxtvc_plugins_textxtvc_option_wrapxtvc_left_sidebar<!-- start mvc wrap --><!-- start right sidebar --><!-- End Right sidebar --><!-- start Left sidebar -->+2 moredata-default-color="#ffffff"id="mv_cr_section_color"jQuery