
AstroBene Security & Risk Analysis
wordpress.org/plugins/astrobeneAstrological weather informer (accurate forecast at once for all zodiac signs) for every day. * Russian.
Is AstroBene Safe to Use in 2026?
Generally Safe
Score 85/100AstroBene has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The astrobene plugin v1.1 exhibits a generally good security posture based on the provided static analysis. The complete absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface, and importantly, all identified entry points lack authentication checks, which is a positive sign. The code signals are also encouraging, with no dangerous functions, no direct SQL queries (all use prepared statements), no file operations, and no external HTTP requests.
However, there are specific areas for improvement. The output escaping is only at 25%, indicating a potential risk of Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is directly outputted without proper sanitization. The lack of nonce checks and capability checks across all entry points (even though the entry points are zero) suggests a potential oversight in the plugin's security implementation, which could become a risk if new entry points are introduced in future versions without these safeguards.
The vulnerability history is a strong positive, with no known CVEs recorded. This, combined with the limited attack surface and good coding practices observed in other areas, suggests that the plugin has been developed with security in mind. Despite the minor concern with output escaping, the overall security of astrobene v1.1 appears to be quite robust.
Key Concerns
- Only 25% of outputs are properly escaped
- No Nonce checks on entry points
- No Capability checks on entry points
AstroBene Security Vulnerabilities
AstroBene Code Analysis
Output Escaping
AstroBene Attack Surface
WordPress Hooks 2
Maintenance & Trust
AstroBene Maintenance & Trust
Maintenance Signals
Community Trust
AstroBene Alternatives
Ephemeris
ephemeris
Adds a sidebar widget that display from the astrological sky the sun sign, the moon sign and the moon phase.
The Daily Horoscope
the-daily-horoscope
Add The Daily Horoscope Plugin to your widgets, posts and pages. Select your sign and read your daily horoscope.
Monthly Horoscopes
monthly-horoscopes
Add up to 12 months of sun sign monthly horoscopes to your sites pages and posts pages with this free and easy to install WordPress plugin.
EZ Horoscope Professional
ez-horoscope
Astrologically accurate horoscopes with cosmic insights, advice, birth charts, and AI voice agents for chatting about readings.
Horoscope widget
daily-horoscope-wp-widget
This is a daily horoscope widget. The widget show 5 stars forecast for every zodiac sign and deep daily horoscope. The content will be pulled from l …
AstroBene Developer Profile
1 plugin · 10 total installs
How We Detect AstroBene
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/astrobene/style.csshttp://feeds.feedburner.com/Astrobene?format=sigpro