Enhanced Import for SportsPress Security & Risk Analysis

wordpress.org/plugins/enhanced-import-for-sportspress

Extends SportsPress CSV importers with score/results support and enhanced functionality for importing fixtures with match outcomes.

50 active installs v1.0 PHP 7.4+ WP 5.3+ Updated Feb 3, 2026
eventsfixturesimportresultsscores
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Enhanced Import for SportsPress Safe to Use in 2026?

Generally Safe

Score 100/100

Enhanced Import for SportsPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The security posture of the "enhanced-import-for-sportspress" v1.0 plugin appears to be generally good based on the provided static analysis. There are no identified dangerous functions, SQL queries are all prepared, and a high percentage of outputs are properly escaped. The presence of a nonce check is also a positive indicator. The absence of external HTTP requests, file operations, and bundled libraries further reduces potential attack vectors.

However, the analysis reveals a complete lack of capability checks and no REST API or AJAX endpoints that enforce permissions. While the attack surface is reported as zero, this may be due to the plugin not exposing any public-facing interactions, or the analysis tool might have limitations in identifying all potential entry points. The taint analysis showing zero flows is also a positive sign, suggesting no obvious vulnerabilities related to untrusted data being processed insecurely.

The plugin's vulnerability history is clean, with no recorded CVEs. This, combined with the static analysis, suggests a relatively low-risk plugin. The main concern is the complete absence of capability checks, which could become a significant risk if any new interaction points are added or if the current analysis doesn't fully capture the attack surface. Despite this, the overall picture is one of a well-developed plugin with a strong focus on secure coding practices.

Key Concerns

  • Missing capability checks on entry points
  • High percentage of unescaped output
Vulnerabilities
None known

Enhanced Import for SportsPress Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Enhanced Import for SportsPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
21 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

81% escaped26 total outputs
Attack Surface

Enhanced Import for SportsPress Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionplugins_loadedenhanced-import-for-sportspress.php:38
actionadmin_noticesincludes\class-eifs-fixture-importer.php:628
actionadmin_noticesincludes\class-eifs-fixture-importer.php:636
filtersportspress_importersincludes\class-eifs-plugin.php:25
Maintenance & Trust

Enhanced Import for SportsPress Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 3, 2026
PHP min version7.4
Downloads412

Community Trust

Rating0/100
Number of ratings0
Active installs50
Developer Profile

Enhanced Import for SportsPress Developer Profile

Savvas

11 plugins · 790 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Enhanced Import for SportsPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/enhanced-import-for-sportspress/assets/css/eifs-admin.css/wp-content/plugins/enhanced-import-for-sportspress/assets/js/eifs-admin.js
Script Paths
/wp-content/plugins/enhanced-import-for-sportspress/assets/js/eifs-admin.js
Version Parameters
enhanced-import-for-sportspress/assets/css/eifs-admin.css?ver=enhanced-import-for-sportspress/assets/js/eifs-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
eifs-import-wrap
Data Attributes
data-sp-formatdata-sp-leaguedata-sp-seasondata-sp-date-format
FAQ

Frequently Asked Questions about Enhanced Import for SportsPress