Astrology Security & Risk Analysis

wordpress.org/plugins/astrology

Turn your Wordpress blog into a full astrology site, powered by Prokerala's astrology API.

600 active installs v1.4.9 PHP 7.2.0+ WP 5.6+ Updated Jan 22, 2026
astrologyprokerala
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Astrology Safe to Use in 2026?

Generally Safe

Score 100/100

Astrology has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The 'astrology' plugin v1.4.9 exhibits a generally good security posture based on the provided static analysis. The absence of dangerous functions, raw SQL queries, and file operations is commendable. Furthermore, the plugin avoids external HTTP requests and bundled libraries, which are common sources of vulnerabilities. The lack of known CVEs and a clean vulnerability history are also positive indicators of the plugin's security.

However, several areas raise concerns. A significant portion of output (86% unescaped) is not properly escaped, presenting a risk of Cross-Site Scripting (XSS) vulnerabilities. The complete absence of nonce checks and capability checks on its entry points, despite having shortcodes, indicates a potential for unauthorized actions or privilege escalation if any of these entry points are ever exposed to user input that is not sufficiently validated upstream. The taint analysis showing zero flows is promising, but this could also be due to a lack of complex data flows being analyzed.

In conclusion, while the plugin's core functionality appears robust against common threats like SQL injection and direct code execution, the significant lack of output escaping and the absence of authentication/authorization checks on its defined entry points are critical weaknesses. Addressing these would substantially improve its security posture. The plugin's clean history is a strength, but the identified code signals warrant careful attention.

Key Concerns

  • High percentage of unescaped output
  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
None known

Astrology Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Astrology Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
747
122 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

14% escaped869 total outputs
Attack Surface

Astrology Attack Surface

Entry Points3
Unprotected0

Shortcodes 3

[astrology] src\Front\Front.php:84
[astrology-form] src\Front\Front.php:85
[astrology-result] src\Front\Front.php:86
WordPress Hooks 14
actionadmin_noticesastrology.php:78
actionadmin_enqueue_scriptssrc\Admin\Admin.php:78
actionadmin_enqueue_scriptssrc\Admin\Admin.php:79
actionadmin_menusrc\Admin\Admin.php:81
actionadmin_noticessrc\Admin\Admin.php:82
actionadmin_initsrc\Admin\Admin.php:83
filterplugin_action_linkssrc\Admin\Admin.php:85
filterplugin_row_metasrc\Admin\Admin.php:86
actionwp_enqueue_scriptssrc\Front\Front.php:81
actionwp_enqueue_scriptssrc\Front\Front.php:82
actionplugins_loadedsrc\Plugin.php:82
actioninitsrc\Plugin.php:151
actionupgrader_process_completesrc\Plugin.php:152
actionpk_astrology_uninstallsrc\Plugin.php:153
Maintenance & Trust

Astrology Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJan 22, 2026
PHP min version7.2.0
Downloads16K

Community Trust

Rating100/100
Number of ratings10
Active installs600
Developer Profile

Astrology Developer Profile

Prokerala

1 plugin · 600 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Astrology

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/astrology/assets/dist/css/admin/settings.css/wp-content/plugins/astrology/assets/dist/js/main.js/wp-content/plugins/astrology/assets/dist/js/admin/settings.js
Script Paths
https://client-api.prokerala.com/static/js/location.min.js
Version Parameters
astrology/assets/dist/css/admin/settings.css?ver=astrology/assets/dist/js/main.js?ver=astrology/assets/dist/js/admin/settings.js?ver=

HTML / DOM Fingerprints

CSS Classes
astrology-settings-wrap
HTML Comments
This file is part of Prokerala Astrology WordPress pluginCopyright (c) 2022 Ennexa Technologies Private Limited
Data Attributes
data-pk-astrology-client-id
JS Globals
window.CLIENT_ID
FAQ

Frequently Asked Questions about Astrology