
BC Kickstarter widget Security & Risk Analysis
wordpress.org/plugins/bc-kickstarter-widgetKickStarter project information directly on your site
Is BC Kickstarter widget Safe to Use in 2026?
Generally Safe
Score 85/100BC Kickstarter widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The bc-kickstarter-widget plugin v1.0 exhibits a generally good security posture based on the provided static analysis. The plugin demonstrates strong practices in handling SQL queries, exclusively using prepared statements, and has no recorded vulnerability history. The absence of dangerous functions, file operations, and external HTTP requests also contributes positively to its security.
However, several areas raise concerns. The lack of nonce checks and capability checks across all entry points is a significant weakness. Coupled with 21 output operations where 76% are properly escaped (meaning 24% are not), this indicates a potential for Cross-Site Scripting (XSS) vulnerabilities. While taint analysis shows no flows with unsanitized paths, this might be due to the limited analysis performed (0 flows analyzed). The presence of one shortcode as an entry point without any authentication or permission checks is also a concern that could be exploited if user-supplied data is handled improperly within it.
In conclusion, while the plugin avoids common pitfalls like vulnerable SQL queries and a history of known exploits, the missing security controls on its entry points and the presence of unescaped output present tangible risks. The absence of observed vulnerabilities in its history is positive but does not guarantee future security, especially with the identified code-level weaknesses.
Key Concerns
- No nonce checks on entry points
- No capability checks on entry points
- Unescaped output (24% of outputs)
- Shortcode entry point without auth
BC Kickstarter widget Security Vulnerabilities
BC Kickstarter widget Release Timeline
BC Kickstarter widget Code Analysis
Output Escaping
BC Kickstarter widget Attack Surface
Shortcodes 1
WordPress Hooks 2
Maintenance & Trust
BC Kickstarter widget Maintenance & Trust
Maintenance Signals
Community Trust
BC Kickstarter widget Alternatives
Contact Form by BestWebSoft – Advanced WP Contact Form Builder for WordPress
contact-form-plugin
The most powerful and user-friendly WordPress contact form plugin. Create beautiful contact forms, widgets and pages using shortcodes.
Apollo13 Framework Extensions
apollo13-framework-extensions
Adds custom post types, shortcodes and some features that are used in themes built on Apollo13 Framework.
Kaya QR Code Generator
kaya-qr-code-generator
Generate QR Code through Widgets and Shortcodes, without any dependencies.
Donations via PayPal
paypal-donations
Easy, simple setup to add a PayPal Donation button as a Widget or with a shortcode.
Reusable Blocks Extended
reusable-blocks-extended
Extend Gutenberg Reusable Blocks feature with a complete admin panel, widgets, shortcodes and PHP functions.
BC Kickstarter widget Developer Profile
1 plugin · 20 total installs
How We Detect BC Kickstarter widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bc-kickstarter-widget/assets/css/kickstarter_css.css/wp-content/plugins/bc-kickstarter-widget/assets/js/kickstarter.js/wp-content/plugins/bc-kickstarter-widget/assets/js/kickstarter.jskickstarter_csskickstarter_jsHTML / DOM Fingerprints
wp_widget_kickstarterdata-url<div id="kickstarter_shortcode" class="wp_widget_kickstarter"