
Dino Game – Embed Google Chrome Dinosaur Game in your website Security & Risk Analysis
wordpress.org/plugins/dino-gameAdd the dinosaur game from Google Chrome to your site using the Dino Game Gutenberg block or [dino-game] shortcode.
Is Dino Game – Embed Google Chrome Dinosaur Game in your website Safe to Use in 2026?
Generally Safe
Score 91/100Dino Game – Embed Google Chrome Dinosaur Game in your website has a strong security track record. Known vulnerabilities have been patched promptly.
The "dino-game" plugin v1.2.0 presents a mixed security posture. On the positive side, the static analysis reveals strong adherence to secure coding practices. All SQL queries are prepared, output is properly escaped, and there are no dangerous functions, file operations, or external HTTP requests detected. The absence of taint analysis findings and zero unprotected entry points are also encouraging signs.
However, the plugin's vulnerability history raises a significant concern. It has a known medium-severity Cross-Site Scripting (XSS) vulnerability, even though it is currently patched. This indicates a past weakness in input sanitization or output escaping that, despite being fixed, suggests a potential for similar issues to arise in the future if development practices are not consistently robust. The lack of nonce checks and capability checks on the single shortcode, while not directly flagged as a vulnerability in the static analysis, leaves room for improvement and a potential attack vector if the shortcode handles user-supplied data that is not otherwise validated or sanitized.
In conclusion, while the current code appears to follow many security best practices, the history of an XSS vulnerability necessitates caution. The plugin exhibits strengths in its clean code regarding direct database interaction and output handling. However, the past CVE and the minimal protection around its single entry point (the shortcode) are areas that require ongoing vigilance and potentially further hardening to ensure a truly secure user experience.
Key Concerns
- Past medium severity XSS vulnerability
- Missing nonce check on shortcode
- Missing capability check on shortcode
Dino Game – Embed Google Chrome Dinosaur Game in your website Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Dino Game – Embed Google Chrome Dinosaur Game in WordPress <= 1.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
Dino Game – Embed Google Chrome Dinosaur Game in your website Code Analysis
Output Escaping
Dino Game – Embed Google Chrome Dinosaur Game in your website Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
Dino Game – Embed Google Chrome Dinosaur Game in your website Maintenance & Trust
Maintenance Signals
Community Trust
Dino Game – Embed Google Chrome Dinosaur Game in your website Alternatives
Dinosaur Game
dinosaur-game
Add the dinosaur game from Google Chrome to your site using the [dinosaur-game] shortcode.
Block-a-saurus
block-a-saurus
Block-a-saurus is a Gutenberg block that lets users play the jumping T-rex game right within a post!
OneSignal – Web Push Notifications
onesignal-free-web-push-notifications
Increase engagement and drive more repeat traffic to your WordPress site with push notifications. Now a WordPress VIP Gold Partner.
Super Progressive Web Apps
super-progressive-web-apps
SuperPWA helps you convert your WordPress website into a Progressive Web App instantly.
WP Menu Icons
wp-menu-icons
WP Menu Icons allows you to add icons to your WordPress menu items.
Dino Game – Embed Google Chrome Dinosaur Game in your website Developer Profile
1 plugin · 300 total installs
How We Detect Dino Game – Embed Google Chrome Dinosaur Game in your website
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/dino-game/dist/dino.build.js/wp-content/plugins/dino-game/src/css/style.css/wp-content/plugins/dino-game/src/img/game-sprites-1x.png/wp-content/plugins/dino-game/src/img/game-sprites-2x.png/wp-content/plugins/dino-game/dist/dino.build.jsdino-game/style.css?ver=dino.build.js?ver=HTML / DOM Fingerprints
dinogame-shortcodedino-game-wrapperdino-icondino-initial-icon<!-- The dinosaur game can only be used once per page. -->data-speeddata-mute-audiodata-save-high-score<div class="dinogame-shortcode">