Draugiem.lv biznesa lapu sekotāju spraudnis Security & Risk Analysis

wordpress.org/plugins/draugiemlvlapas-fan-page

Draugiem.lv biznesa lapu un pasākumu fanu WordPress spraudnis draugiem.lv lietotājiem

10 active installs v3.5.4 PHP + WP 3.3+ Updated Jul 31, 2017
draugiemdraugiem-lvfrypesidebarwidget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Draugiem.lv biznesa lapu sekotāju spraudnis Safe to Use in 2026?

Generally Safe

Score 85/100

Draugiem.lv biznesa lapu sekotāju spraudnis has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The 'draugiemlvlapas-fan-page' plugin version 3.5.4 demonstrates a generally good security posture based on the provided static analysis. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests is a strong positive indicator. Furthermore, the plugin boasts a small attack surface with only two shortcodes, and crucially, no identified entry points are unprotected.

However, the analysis does reveal a significant concern regarding output escaping. With 91 total outputs and only 9% properly escaped, there's a high likelihood of Cross-Site Scripting (XSS) vulnerabilities. This is a critical weakness that could be exploited by attackers to inject malicious scripts into users' browsers. The complete lack of nonce and capability checks, while not directly exposed in the entry points, could become a vector for privilege escalation or unauthorized actions if vulnerabilities are found elsewhere or if the shortcodes are used in contexts where these checks are bypassed.

The plugin's vulnerability history is clean, with no recorded CVEs, which is commendable. This, combined with the absence of taint flows and dangerous functions, suggests the developers may be following good coding practices. Nevertheless, the poor output escaping remains a glaring issue that needs immediate attention. The plugin's strengths lie in its limited attack surface and absence of known critical vulnerabilities, but its weakness in output sanitization presents a tangible risk.

Key Concerns

  • Poor output escaping
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Draugiem.lv biznesa lapu sekotāju spraudnis Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Draugiem.lv biznesa lapu sekotāju spraudnis Release Timeline

v3.5.4Current
v3.5.3
v3.5.2
v3.5.1
v3.5.0
v3.0.1
v3.0
v2.3.0
v2.2.3
v2.2.2
v2.2.1
v2.2
v2.1
v2.0
v0.2.1
v0.2
v0.1.8
v0.1.7
v0.1.6
v0.1.5.1
Code Analysis
Analyzed Mar 17, 2026

Draugiem.lv biznesa lapu sekotāju spraudnis Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
83
8 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

9% escaped91 total outputs
Attack Surface

Draugiem.lv biznesa lapu sekotāju spraudnis Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[frypeevent] frypeevents_widget.php:20
[frypevent] frypeevents_widget.php:21
WordPress Hooks 6
actionwidgets_initfrypeevents_widget.php:22
actionwidgets_initfrypepage.php:77
actioninitfrypepage.php:78
actionplugin_row_metafrypepage.php:79
actionfrypefansfrypepage.php:80
actionwp_headfrypepage.php:81
Maintenance & Trust

Draugiem.lv biznesa lapu sekotāju spraudnis Maintenance & Trust

Maintenance Signals

WordPress version tested4.8.28
Last updatedJul 31, 2017
PHP min version
Downloads5K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Draugiem.lv biznesa lapu sekotāju spraudnis Developer Profile

Umbrovskis.com

2 plugins · 710 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Draugiem.lv biznesa lapu sekotāju spraudnis

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/draugiemlvlapas-fan-page/css/draugiem-lapas-sekotaji.css
Generator Patterns
https://mediabox.lv/wordpress-spraudni/?utm_source=draugiemlvlapas-fan-page-3.5.4
Script Paths
//www.draugiem.lv/api/api.js
Version Parameters
draugiemlvlapas-fan-page/css/draugiem-lapas-sekotaji.css?ver=

HTML / DOM Fingerprints

HTML Comments
Draugiem.lv biznesa lapu sekotāju spraudnis via https://Umbrovskis.com | https://MediaBox.lv | https://SimpleMediaCode.com / Draugiem.lv biznesa lapu sekotāju spraudnis via https://Umbrovskis.com | https://MediaBox.lv | https://SimpleMediaCode.com / beigas
Data Attributes
id="fansblock
JS Globals
DApi.BizFans
Shortcode Output
<style>#fansblockvar fans2 = new DApi.BizFans({
FAQ

Frequently Asked Questions about Draugiem.lv biznesa lapu sekotāju spraudnis