
BZScore – Live Score Security & Risk Analysis
wordpress.org/plugins/bzscore-live-scoreBZScore - Live Scores. Get a livescore page. No Ads, no iFrames, fully customizable and responsive. The plugin developed by livescore.bz.
Is BZScore – Live Score Safe to Use in 2026?
Generally Safe
Score 85/100BZScore – Live Score has a strong security track record. Known vulnerabilities have been patched promptly.
The "bzscore-live-score" plugin, version 1.6.0, exhibits a mixed security posture. On the positive side, the static analysis reveals strong adherence to secure coding practices, with 100% of SQL queries using prepared statements and all output being properly escaped. There are no identified dangerous functions, file operations, or external HTTP requests, and the plugin's attack surface is minimal, consisting solely of one shortcode without any readily apparent unauthenticated entry points. This suggests a foundational understanding of secure development within the plugin's code.
However, a significant concern arises from the vulnerability history. The plugin has a documented medium-severity Cross-Site Scripting (XSS) vulnerability, with the last known vulnerability occurring in November 2023. The fact that this vulnerability is no longer present in the analyzed version (unpatched count is 0) is a good sign, but the existence of past XSS issues, even if remediated, indicates a potential area where input sanitization or output encoding might have been overlooked in previous versions or could be reintroduced if not thoroughly tested. The complete lack of taint analysis results is also notable; while this could indicate the absence of complex data flows, it might also mean that the analysis tooling did not detect any flows, which doesn't necessarily equate to a complete absence of risk if the analysis scope was limited.
In conclusion, while version 1.6.0 of "bzscore-live-score" demonstrates good security hygiene regarding SQL and output escaping, the historical XSS vulnerability warrants careful consideration. The plugin's limited attack surface and good coding practices in the current version are strengths. However, the past vulnerability suggests a need for ongoing vigilance and robust testing to prevent the reintroduction of such issues. The absence of critical or high-severity vulnerabilities in the current static analysis is positive, but the historical context should not be ignored.
Key Concerns
- Past medium severity XSS vulnerability
- Zero taint flows analyzed
- No nonce checks implemented
- No capability checks implemented
BZScore – Live Score Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
BZScore – Live Score <= 1.03 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode
BZScore – Live Score Code Analysis
Output Escaping
BZScore – Live Score Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
BZScore – Live Score Maintenance & Trust
Maintenance Signals
Community Trust
BZScore – Live Score Alternatives
AZScore: Live Score and football fixures and results
azscore
AZScore - provides real-time soccer match scores. Completely ad-free, without iFrames, fully customizable, and responsive.
ProScores – Live Scores
proscores-live-scores
ProScores provides a fully customizable and responsive live scores page, free of ads and iframes. Developed by Livescores.pro
Scores – Livescore for football, soccer, tennis, basketball, handball, volleyball & hockey
live-scores
Livescores with NO ADS! Display our free livescore widget for Soccer, American Football (NFL,CFL), Tennis (APT,WTA), Basketball, Handball, Volleyball …
Cric Zumo Cricket Scoreboards and Odds Plugin
cric-zumo
We provide fastest scoreboards and livescores
Live Score
live-score
This plugin adds online live scores to your blog.
BZScore – Live Score Developer Profile
1 plugin · 800 total installs
How We Detect BZScore – Live Score
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bzscore-live-score/bzscore.css/wp-content/plugins/bzscore-live-score/bzscore.js/wp-content/plugins/bzscore-live-score/bzscore.jsbzscore.css?ver=bzscore.js?ver=HTML / DOM Fingerprints
bzscore-live-score-container<!-- START BZSCORE LIVE SCORE SETTINGS --><!-- END BZSCORE LIVE SCORE SETTINGS -->data-2league-iscountry-isbzscore_settings[bzscore][bzscore font-size[bzscore font-family[bzscore data-2="league"