
Astrology Security & Risk Analysis
wordpress.org/plugins/astrologyTurn your Wordpress blog into a full astrology site, powered by Prokerala's astrology API.
Is Astrology Safe to Use in 2026?
Generally Safe
Score 100/100Astrology has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'astrology' plugin v1.4.9 exhibits a generally good security posture based on the provided static analysis. The absence of dangerous functions, raw SQL queries, and file operations is commendable. Furthermore, the plugin avoids external HTTP requests and bundled libraries, which are common sources of vulnerabilities. The lack of known CVEs and a clean vulnerability history are also positive indicators of the plugin's security.
However, several areas raise concerns. A significant portion of output (86% unescaped) is not properly escaped, presenting a risk of Cross-Site Scripting (XSS) vulnerabilities. The complete absence of nonce checks and capability checks on its entry points, despite having shortcodes, indicates a potential for unauthorized actions or privilege escalation if any of these entry points are ever exposed to user input that is not sufficiently validated upstream. The taint analysis showing zero flows is promising, but this could also be due to a lack of complex data flows being analyzed.
In conclusion, while the plugin's core functionality appears robust against common threats like SQL injection and direct code execution, the significant lack of output escaping and the absence of authentication/authorization checks on its defined entry points are critical weaknesses. Addressing these would substantially improve its security posture. The plugin's clean history is a strength, but the identified code signals warrant careful attention.
Key Concerns
- High percentage of unescaped output
- No nonce checks on entry points
- No capability checks on entry points
Astrology Security Vulnerabilities
Astrology Code Analysis
Output Escaping
Astrology Attack Surface
Shortcodes 3
WordPress Hooks 14
Maintenance & Trust
Astrology Maintenance & Trust
Maintenance Signals
Community Trust
Astrology Alternatives
Moon Phases
moon-phases
Adds a sidebar widget that display the current moon phase.
EZ Horoscope Professional
ez-horoscope
Astrologically accurate horoscopes with cosmic insights, advice, birth charts, and AI voice agents for chatting about readings.
The Daily Horoscope
the-daily-horoscope
Add The Daily Horoscope Plugin to your widgets, posts and pages. Select your sign and read your daily horoscope.
WP Moon Phase Widget
wp-moon-phase-widget
Moon phase widget for Wordpress
Ephemeris
ephemeris
Adds a sidebar widget that display from the astrological sky the sun sign, the moon sign and the moon phase.
Astrology Developer Profile
1 plugin · 600 total installs
How We Detect Astrology
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/astrology/assets/dist/css/admin/settings.css/wp-content/plugins/astrology/assets/dist/js/main.js/wp-content/plugins/astrology/assets/dist/js/admin/settings.jshttps://client-api.prokerala.com/static/js/location.min.jsastrology/assets/dist/css/admin/settings.css?ver=astrology/assets/dist/js/main.js?ver=astrology/assets/dist/js/admin/settings.js?ver=HTML / DOM Fingerprints
astrology-settings-wrapThis file is part of Prokerala Astrology WordPress pluginCopyright (c) 2022 Ennexa Technologies Private Limiteddata-pk-astrology-client-idwindow.CLIENT_ID