AstroBene Security & Risk Analysis

wordpress.org/plugins/astrobene

Astrological weather informer (accurate forecast at once for all zodiac signs) for every day. * Russian.

10 active installs v1.1 PHP 5.4+ WP 3.0.1+ Updated Jan 27, 2022
astrological-reportastrological-reportsastrologyhoroscopehoroscopes
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is AstroBene Safe to Use in 2026?

Generally Safe

Score 85/100

AstroBene has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The astrobene plugin v1.1 exhibits a generally good security posture based on the provided static analysis. The complete absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface, and importantly, all identified entry points lack authentication checks, which is a positive sign. The code signals are also encouraging, with no dangerous functions, no direct SQL queries (all use prepared statements), no file operations, and no external HTTP requests.

However, there are specific areas for improvement. The output escaping is only at 25%, indicating a potential risk of Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is directly outputted without proper sanitization. The lack of nonce checks and capability checks across all entry points (even though the entry points are zero) suggests a potential oversight in the plugin's security implementation, which could become a risk if new entry points are introduced in future versions without these safeguards.

The vulnerability history is a strong positive, with no known CVEs recorded. This, combined with the limited attack surface and good coding practices observed in other areas, suggests that the plugin has been developed with security in mind. Despite the minor concern with output escaping, the overall security of astrobene v1.1 appears to be quite robust.

Key Concerns

  • Only 25% of outputs are properly escaped
  • No Nonce checks on entry points
  • No Capability checks on entry points
Vulnerabilities
None known

AstroBene Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

AstroBene Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

25% escaped8 total outputs
Attack Surface

AstroBene Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionwp_enqueue_scriptsastrobene.php:16
actionwidgets_initastrobene.php:80
Maintenance & Trust

AstroBene Maintenance & Trust

Maintenance Signals

WordPress version tested5.9.13
Last updatedJan 27, 2022
PHP min version5.4
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

AstroBene Developer Profile

C-In-OFF

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect AstroBene

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/astrobene/style.css
Script Paths
http://feeds.feedburner.com/Astrobene?format=sigpro

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about AstroBene