Arena.IM – Live Blogging for real-time events Security & Risk Analysis

wordpress.org/plugins/arena-liveblog-and-chat-tool

Arena.im is a powerful FREE live blogging platform for real-time events. Cover sports, news, tech, etc. SEO optimized and mobile ready.

200 active installs v0.4.2 PHP + WP 3.6.1+ Updated Mar 11, 2025
live-bloglive-blogginglivebloglivebloggingreal-time
49
D · High Risk
CVEs total3
Unpatched2
Last CVEDec 11, 2024
Safety Verdict

Is Arena.IM – Live Blogging for real-time events Safe to Use in 2026?

High Risk

Score 49/100

Arena.IM – Live Blogging for real-time events carries significant security risk with 3 known CVEs, 2 still unpatched. Consider switching to a maintained alternative.

3 known CVEs 2 unpatched Last CVE: Dec 11, 2024Updated 1yr ago
Risk Assessment

The arena-liveblog-and-chat-tool plugin v0.4.2 presents a moderate security risk. While it demonstrates some good practices, such as using prepared statements for all SQL queries and a relatively high rate of output escaping, several concerning aspects significantly increase its vulnerability. The presence of three AJAX handlers without authentication checks provides a direct attack vector for unauthenticated users to potentially interact with plugin functionalities. Additionally, two flows with unsanitized paths identified in the taint analysis, though not classified as critical or high severity, suggest a potential for input manipulation that could lead to unexpected behavior or vulnerabilities.

The plugin's vulnerability history is a major red flag. With a total of three known CVEs, two of which remain unpatched, and a recent vulnerability reported in late 2024, this indicates a pattern of security flaws. The common vulnerability types being Cross-Site Request Forgery (CSRF) and Cross-site Scripting (XSS) further emphasize the risks associated with improper input handling and authorization.

In conclusion, while the plugin's commitment to prepared SQL statements and decent output escaping are positive, the unprotected AJAX endpoints, unsanitized input paths, and a history of unpatched vulnerabilities necessitate caution. The ongoing unpatched vulnerabilities are the most significant concern, and their presence on a recent date suggests a lack of active security maintenance.

Key Concerns

  • 3 AJAX handlers without auth checks
  • 2 flows with unsanitized paths
  • 2 unpatched CVEs
  • 0 Nonce checks on AJAX
  • 1 Capability check found
Vulnerabilities
3 published

Arena.IM – Live Blogging for real-time events Security Vulnerabilities

CVEs by Year

3 CVEs in 2024 · unpatched
2024
Patched Has unpatched

Severity Breakdown

Medium
3

3 total CVEs

CVE-2024-12526medium · 4.3Cross-Site Request Forgery (CSRF)

Arena.IM – Live Blogging for real-time events <= 0.4.1 - Cross-Site Request Forgery to Settings Update

Dec 11, 2024Unpatched
CVE-2024-12463medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Arena.IM – Live Blogging for real-time events <= 0.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via arena_embed_amp Shortcode

Dec 11, 2024Unpatched
CVE-2024-11384medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Arena.IM – Live Blogging for real-time events <= 0.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

Dec 11, 2024 Patched in 0.4.0 (50d)
Code Analysis
Analyzed Mar 16, 2026

Arena.IM – Live Blogging for real-time events Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
23
59 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

72% escaped82 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

3 flows2 with unsanitized paths
albfre_set_account_action (albfre.php:151)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
3 unprotected

Arena.IM – Live Blogging for real-time events Attack Surface

Entry Points7
Unprotected3

AJAX Handlers 3

authwp_ajax_albfre_user_actionalbfre.php:30
authwp_ajax_albfre_set_account_actionalbfre.php:31
authwp_ajax_albfre_logout_actionalbfre.php:32

Shortcodes 4

[arena_embed] albfre.php:202
[arena_embed_amp] albfre.php:203
[arena_embed_iframe] albfre.php:204
[arenablog] shortcode\init.php:116
WordPress Hooks 18
actioninitalbfre.php:26
actionadmin_noticesalbfre.php:27
actionadmin_menualbfre.php:28
actionadmin_enqueue_scriptsalbfre.php:29
actionadmin_headalbfre.php:129
actioninitalbfre.php:197
actionmedia_buttonsalbfre.php:198
actionadmin_menualbfre.php:199
actionadmin_enqueue_scriptsalbfre.php:200
actionwp_enqueue_scriptsalbfre.php:201
actioninitgutenberg\arena-block\src\init.php:90
filterblock_categoriesgutenberg\init.php:8
actionenqueue_block_editor_assetsgutenberg\init.php:116
filtercron_schedulesshortcode\cron.php:11
actionadmin_noticesshortcode\init.php:10
actionarena_events_update_dateshortcode\init.php:11
actionpost_updatedshortcode\init.php:260
filterwp_insert_post_datashortcode\init.php:263

Scheduled Events 1

arena_events_update_date
Maintenance & Trust

Arena.IM – Live Blogging for real-time events Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedMar 11, 2025
PHP min version
Downloads18K

Community Trust

Rating80/100
Number of ratings10
Active installs200
Developer Profile

Arena.IM – Live Blogging for real-time events Developer Profile

Arena.IM

2 plugins · 210 total installs

68
trust score
Avg Security Score
71/100
Avg Patch Time
50 days
View full developer profile
Detection Fingerprints

How We Detect Arena.IM – Live Blogging for real-time events

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/arena-liveblog-and-chat-tool/assets/albfre_notice.css/wp-content/plugins/arena-liveblog-and-chat-tool/assets/albfre_admin.css/wp-content/plugins/arena-liveblog-and-chat-tool/assets/albfre_admin.js
Script Paths
/wp-content/plugins/arena-liveblog-and-chat-tool/assets/albfre_admin.js
Version Parameters
/arena-liveblog-and-chat-tool/assets/albfre_notice.css?ver=/arena-liveblog-and-chat-tool/assets/albfre_admin.css?ver=/arena-liveblog-and-chat-tool/assets/albfre_admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
albfre-liveblogarena-liveblogarena-embed
Data Attributes
data-arena-embed-iddata-arena-embed-slug
JS Globals
albfre_settings_object
Shortcode Output
[arena_embed][arena_embed_amp][arena_embed_iframe]
FAQ

Frequently Asked Questions about Arena.IM – Live Blogging for real-time events