Dino Game – Embed Google Chrome Dinosaur Game in your website Security & Risk Analysis

wordpress.org/plugins/dino-game

Add the dinosaur game from Google Chrome to your site using the Dino Game Gutenberg block or [dino-game] shortcode.

300 active installs v1.2.0 PHP 7.3+ WP 5.0+ Updated Nov 21, 2024
chromedinodinosaurgametrex
91
A · Safe
CVEs total1
Unpatched0
Last CVENov 20, 2024
Safety Verdict

Is Dino Game – Embed Google Chrome Dinosaur Game in your website Safe to Use in 2026?

Generally Safe

Score 91/100

Dino Game – Embed Google Chrome Dinosaur Game in your website has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Nov 20, 2024Updated 1yr ago
Risk Assessment

The "dino-game" plugin v1.2.0 presents a mixed security posture. On the positive side, the static analysis reveals strong adherence to secure coding practices. All SQL queries are prepared, output is properly escaped, and there are no dangerous functions, file operations, or external HTTP requests detected. The absence of taint analysis findings and zero unprotected entry points are also encouraging signs.

However, the plugin's vulnerability history raises a significant concern. It has a known medium-severity Cross-Site Scripting (XSS) vulnerability, even though it is currently patched. This indicates a past weakness in input sanitization or output escaping that, despite being fixed, suggests a potential for similar issues to arise in the future if development practices are not consistently robust. The lack of nonce checks and capability checks on the single shortcode, while not directly flagged as a vulnerability in the static analysis, leaves room for improvement and a potential attack vector if the shortcode handles user-supplied data that is not otherwise validated or sanitized.

In conclusion, while the current code appears to follow many security best practices, the history of an XSS vulnerability necessitates caution. The plugin exhibits strengths in its clean code regarding direct database interaction and output handling. However, the past CVE and the minimal protection around its single entry point (the shortcode) are areas that require ongoing vigilance and potentially further hardening to ensure a truly secure user experience.

Key Concerns

  • Past medium severity XSS vulnerability
  • Missing nonce check on shortcode
  • Missing capability check on shortcode
Vulnerabilities
1

Dino Game – Embed Google Chrome Dinosaur Game in your website Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-11388medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Dino Game – Embed Google Chrome Dinosaur Game in WordPress <= 1.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

Nov 20, 2024 Patched in 1.2.0 (2d)
Code Analysis
Analyzed Mar 16, 2026

Dino Game – Embed Google Chrome Dinosaur Game in your website Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
3 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped3 total outputs
Attack Surface

Dino Game – Embed Google Chrome Dinosaur Game in your website Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[dino-game] dino-game.php:39
WordPress Hooks 3
actionwp_enqueue_scriptsdino-game.php:33
actionenqueue_block_editor_assetsdino-game.php:139
actionenqueue_block_assetsdino-game.php:169
Maintenance & Trust

Dino Game – Embed Google Chrome Dinosaur Game in your website Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedNov 21, 2024
PHP min version7.3
Downloads42K

Community Trust

Rating100/100
Number of ratings3
Active installs300
Developer Profile

Dino Game – Embed Google Chrome Dinosaur Game in your website Developer Profile

Tahmid ul Karim

1 plugin · 300 total installs

94
trust score
Avg Security Score
91/100
Avg Patch Time
2 days
View full developer profile
Detection Fingerprints

How We Detect Dino Game – Embed Google Chrome Dinosaur Game in your website

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/dino-game/dist/dino.build.js/wp-content/plugins/dino-game/src/css/style.css/wp-content/plugins/dino-game/src/img/game-sprites-1x.png/wp-content/plugins/dino-game/src/img/game-sprites-2x.png
Script Paths
/wp-content/plugins/dino-game/dist/dino.build.js
Version Parameters
dino-game/style.css?ver=dino.build.js?ver=

HTML / DOM Fingerprints

CSS Classes
dinogame-shortcodedino-game-wrapperdino-icondino-initial-icon
HTML Comments
<!-- The dinosaur game can only be used once per page. -->
Data Attributes
data-speeddata-mute-audiodata-save-high-score
Shortcode Output
<div class="dinogame-shortcode">
FAQ

Frequently Asked Questions about Dino Game – Embed Google Chrome Dinosaur Game in your website