BZScore – Live Score Security & Risk Analysis

wordpress.org/plugins/bzscore-live-score

BZScore - Live Scores. Get a livescore page. No Ads, no iFrames, fully customizable and responsive. The plugin developed by livescore.bz.

800 active installs v1.6.0 PHP + WP 3.5+ Updated Mar 8, 2024
footballlivelivescorescorescores
85
A · Safe
CVEs total1
Unpatched0
Last CVENov 7, 2023
Safety Verdict

Is BZScore – Live Score Safe to Use in 2026?

Generally Safe

Score 85/100

BZScore – Live Score has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Nov 7, 2023Updated 2yr ago
Risk Assessment

The "bzscore-live-score" plugin, version 1.6.0, exhibits a mixed security posture. On the positive side, the static analysis reveals strong adherence to secure coding practices, with 100% of SQL queries using prepared statements and all output being properly escaped. There are no identified dangerous functions, file operations, or external HTTP requests, and the plugin's attack surface is minimal, consisting solely of one shortcode without any readily apparent unauthenticated entry points. This suggests a foundational understanding of secure development within the plugin's code.

However, a significant concern arises from the vulnerability history. The plugin has a documented medium-severity Cross-Site Scripting (XSS) vulnerability, with the last known vulnerability occurring in November 2023. The fact that this vulnerability is no longer present in the analyzed version (unpatched count is 0) is a good sign, but the existence of past XSS issues, even if remediated, indicates a potential area where input sanitization or output encoding might have been overlooked in previous versions or could be reintroduced if not thoroughly tested. The complete lack of taint analysis results is also notable; while this could indicate the absence of complex data flows, it might also mean that the analysis tooling did not detect any flows, which doesn't necessarily equate to a complete absence of risk if the analysis scope was limited.

In conclusion, while version 1.6.0 of "bzscore-live-score" demonstrates good security hygiene regarding SQL and output escaping, the historical XSS vulnerability warrants careful consideration. The plugin's limited attack surface and good coding practices in the current version are strengths. However, the past vulnerability suggests a need for ongoing vigilance and robust testing to prevent the reintroduction of such issues. The absence of critical or high-severity vulnerabilities in the current static analysis is positive, but the historical context should not be ignored.

Key Concerns

  • Past medium severity XSS vulnerability
  • Zero taint flows analyzed
  • No nonce checks implemented
  • No capability checks implemented
Vulnerabilities
1

BZScore – Live Score Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2023-47654medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BZScore – Live Score <= 1.03 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode

Nov 7, 2023 Patched in 1.6.0 (843d)
Code Analysis
Analyzed Mar 16, 2026

BZScore – Live Score Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
29 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped29 total outputs
Attack Surface

BZScore – Live Score Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[bzscore] bzscore.php:612
WordPress Hooks 3
actionadmin_menubzscore.php:50
actionadmin_initbzscore.php:53
actionadmin_enqueue_scriptsbzscore.php:56
Maintenance & Trust

BZScore – Live Score Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedMar 8, 2024
PHP min version
Downloads38K

Community Trust

Rating100/100
Number of ratings10
Active installs800
Developer Profile

BZScore – Live Score Developer Profile

firstsport

1 plugin · 800 total installs

69
trust score
Avg Security Score
85/100
Avg Patch Time
843 days
View full developer profile
Detection Fingerprints

How We Detect BZScore – Live Score

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bzscore-live-score/bzscore.css/wp-content/plugins/bzscore-live-score/bzscore.js
Script Paths
/wp-content/plugins/bzscore-live-score/bzscore.js
Version Parameters
bzscore.css?ver=bzscore.js?ver=

HTML / DOM Fingerprints

CSS Classes
bzscore-live-score-container
HTML Comments
<!-- START BZSCORE LIVE SCORE SETTINGS --><!-- END BZSCORE LIVE SCORE SETTINGS -->
Data Attributes
data-2league-iscountry-is
JS Globals
bzscore_settings
Shortcode Output
[bzscore][bzscore font-size[bzscore font-family[bzscore data-2="league"
FAQ

Frequently Asked Questions about BZScore – Live Score