
Cricket Live Score Security & Risk Analysis
wordpress.org/plugins/cricket-scoreGet the latest auto-updated live Cricket Score for your website for free.
Is Cricket Live Score Safe to Use in 2026?
Generally Safe
Score 91/100Cricket Live Score has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "cricket-score" plugin version 2.0.3 demonstrates some positive security practices, including 100% of its SQL queries using prepared statements and all identified outputs being properly escaped. The absence of critical or high severity taint flows, along with no dangerous functions or external HTTP requests, suggests a generally secure codebase in these areas.
However, there are notable concerns. The plugin has a history of vulnerabilities, with one medium severity Cross-Site Scripting (XSS) issue recorded. While currently unpatched CVEs are zero, this history indicates a recurring pattern of potential security weaknesses. Furthermore, the static analysis reveals a complete lack of nonce checks and capability checks, which is a significant concern for entry points like shortcodes. Although the static analysis indicates no unprotected entry points, the absence of these checks means that the existing shortcode is vulnerable to unauthorized execution if an attacker can trick a user into triggering it.
In conclusion, while the plugin has strengths in its SQL and output handling, the history of vulnerabilities and the critical absence of nonce and capability checks on its shortcode create a moderate to high risk. The plugin should be reviewed and updated to include proper authorization checks to mitigate the risks associated with its vulnerability history and lack of input validation.
Key Concerns
- Medium severity XSS vulnerability in history
- No nonce checks on entry points
- No capability checks on entry points
Cricket Live Score Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Cricket Live Score <= 2.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
Cricket Live Score Release Timeline
Cricket Live Score Code Analysis
Output Escaping
Cricket Live Score Attack Surface
Shortcodes 1
WordPress Hooks 2
Maintenance & Trust
Cricket Live Score Maintenance & Trust
Maintenance Signals
Community Trust
Cricket Live Score Alternatives
Cric Zumo Cricket Scoreboards and Odds Plugin
cric-zumo
We provide fastest scoreboards and livescores
BNS Corner Logo
bns-corner-logo
Widget to display a logo; or, used as a plugin displays image fixed in one of the four corners.
AZScore: Live Score and football fixures and results
azscore
AZScore - provides real-time soccer match scores. Completely ad-free, without iFrames, fully customizable, and responsive.
Multi Image Widget
multi-image-widget
Multi image widget is used to upload the multiple image.
BNS SMF Feeds
bns-smf-feeds
Plugin with multi-widget functionality that builds an SMF Forum RSS feed url by user option choices; and, displays a SMF forum feed.
Cricket Live Score Developer Profile
1 plugin · 200 total installs
How We Detect Cricket Live Score
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
wrapmetabox-holderwidget[cricket_score][cricket_score period=live][cricket_score height=800][cricket_score height=1500]