Cricket Live Score Security & Risk Analysis

wordpress.org/plugins/cricket-score

Get the latest auto-updated live Cricket Score for your website for free.

200 active installs v2.0.3 PHP 7.0+ WP 4.1+ Updated Feb 18, 2025
cricketipllive-scorelivescorewidget
91
A · Safe
CVEs total1
Unpatched0
Last CVEDec 13, 2024
Safety Verdict

Is Cricket Live Score Safe to Use in 2026?

Generally Safe

Score 91/100

Cricket Live Score has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Dec 13, 2024Updated 1yr ago
Risk Assessment

The "cricket-score" plugin version 2.0.3 demonstrates some positive security practices, including 100% of its SQL queries using prepared statements and all identified outputs being properly escaped. The absence of critical or high severity taint flows, along with no dangerous functions or external HTTP requests, suggests a generally secure codebase in these areas.

However, there are notable concerns. The plugin has a history of vulnerabilities, with one medium severity Cross-Site Scripting (XSS) issue recorded. While currently unpatched CVEs are zero, this history indicates a recurring pattern of potential security weaknesses. Furthermore, the static analysis reveals a complete lack of nonce checks and capability checks, which is a significant concern for entry points like shortcodes. Although the static analysis indicates no unprotected entry points, the absence of these checks means that the existing shortcode is vulnerable to unauthorized execution if an attacker can trick a user into triggering it.

In conclusion, while the plugin has strengths in its SQL and output handling, the history of vulnerabilities and the critical absence of nonce and capability checks on its shortcode create a moderate to high risk. The plugin should be reviewed and updated to include proper authorization checks to mitigate the risks associated with its vulnerability history and lack of input validation.

Key Concerns

  • Medium severity XSS vulnerability in history
  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
1 published

Cricket Live Score Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-11877medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Cricket Live Score <= 2.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

Dec 13, 2024 Patched in 2.0.3 (69d)
Version History

Cricket Live Score Release Timeline

v2.0.3Current
v2.0.21 CVE
v2.0.11 CVE
v2.0.01 CVE
v1.0.21 CVE
v1.0.11 CVE
v1.0.01 CVE
Code Analysis
Analyzed Mar 16, 2026

Cricket Live Score Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
13 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped13 total outputs
Attack Surface

Cricket Live Score Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[cricket_score] cricket-score.php:17
WordPress Hooks 2
actionadmin_menusrc\FscoreConfig.php:43
actionadmin_initsrc\FscoreConfig.php:46
Maintenance & Trust

Cricket Live Score Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedFeb 18, 2025
PHP min version7.0
Downloads12K

Community Trust

Rating74/100
Number of ratings3
Active installs200
Developer Profile

Cricket Live Score Developer Profile

wpscore

1 plugin · 200 total installs

82
trust score
Avg Security Score
91/100
Avg Patch Time
69 days
View full developer profile
Detection Fingerprints

How We Detect Cricket Live Score

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
wrapmetabox-holderwidget
Shortcode Output
[cricket_score][cricket_score period=live][cricket_score height=800][cricket_score height=1500]
FAQ

Frequently Asked Questions about Cricket Live Score