
WP Battle by Alex Lundin Security & Risk Analysis
wordpress.org/plugins/battle-by-alex-lundinHere is a short description of the plugin. This should be no more than 150 characters. No markup here.
Is WP Battle by Alex Lundin Safe to Use in 2026?
Generally Safe
Score 85/100WP Battle by Alex Lundin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'battle-by-alex-lundin' plugin v1.0.1 presents a mixed security posture. On the positive side, it demonstrates good practices regarding output escaping, with all outputs being properly sanitized. It also avoids dangerous functions, file operations, and external HTTP requests, which are common sources of vulnerabilities. The absence of any known CVEs, past or present, and no recorded common vulnerability types further suggest a generally stable codebase. However, a significant concern arises from the unprotected attack surface. A large proportion of the plugin's entry points, specifically all 6 REST API routes, lack proper permission callbacks, exposing them to potential unauthorized access and manipulation. Additionally, the complete absence of nonce checks is a critical oversight, especially when combined with unprotected entry points, as it leaves the plugin vulnerable to Cross-Site Request Forgery (CSRF) attacks. The 40% of SQL queries not using prepared statements also represent a potential risk for SQL injection vulnerabilities, though this is mitigated somewhat by the presence of capability checks for some operations.
Key Concerns
- REST API routes without permission callbacks
- Missing nonce checks
- SQL queries without prepared statements
WP Battle by Alex Lundin Security Vulnerabilities
WP Battle by Alex Lundin Code Analysis
SQL Query Safety
Output Escaping
WP Battle by Alex Lundin Attack Surface
REST API Routes 6
Shortcodes 1
WordPress Hooks 11
Maintenance & Trust
WP Battle by Alex Lundin Maintenance & Trust
Maintenance Signals
Community Trust
WP Battle by Alex Lundin Alternatives
Akismet Anti-spam: Spam Protection
akismet
The best anti-spam protection to block spam comments and spam in a contact form. The most trusted antispam solution for WordPress and WooCommerce.
Disable Comments – Remove Comments & Stop Spam [Multi-Site Support]
disable-comments
Allows administrators to globally disable comments on their site. Comments can be disabled according to post type. Multisite friendly.
Antispam Bee
antispam-bee
Sophisticated antispam plugin for effective daily comment and trackback spam-fighting. Built with data protection and privacy in mind.
Spam protection, Honeypot, Anti-Spam by CleanTalk
cleantalk-spam-protect
Blocks spam comments, fake users, contact form spam and more. No impact on SEO. Privacy focused. CAPTCHA free, premium Antispam plugin.
Captcha Code
captcha-code-authentication
GDPR compatible captcha anti-spam protection for login form, comments form, registration form & lost password form. Eliminate spam with captcha.
WP Battle by Alex Lundin Developer Profile
3 plugins · 10 total installs
How We Detect WP Battle by Alex Lundin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/battle-by-alex-lundin/admin/frontend/build/index.css/wp-content/plugins/battle-by-alex-lundin/admin/frontend/build/index.js/battle-by-alex-lundin/admin/frontend/build/index.css?ver=/battle-by-alex-lundin/admin/frontend/build/index.js?ver=HTML / DOM Fingerprints
data-reactrootasl_battles_admin/wp-json/wp/v2/users