EV Crosswords Security & Risk Analysis

wordpress.org/plugins/ev-crosswords

Easily add crosswords to your Wordpress website, with or without AI help.

10 active installs v2.0.7 PHP 8.1+ WP 6.7+ Updated Apr 12, 2026
crosswordsentertainmentword-games
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is EV Crosswords Safe to Use in 2026?

Generally Safe

Score 100/100

EV Crosswords has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The 'ev-crosswords' plugin version 2.0.5 exhibits a generally good security posture based on the provided static analysis and vulnerability history. The absence of any recorded CVEs, along with the fact that all identified SQL queries use prepared statements, indicates strong development practices in these areas. The plugin also implements capability checks for its entry points and has a low overall attack surface with no directly unprotected entry points found.

However, there are a few areas that warrant attention. The 67% output escaping rate means that nearly a third of all output operations are not properly escaped, potentially leading to cross-site scripting (XSS) vulnerabilities. While no specific taint flows were identified, this lack of complete output escaping significantly increases the risk of XSS if user-supplied data is involved in any of the unescaped outputs. The presence of external HTTP requests also introduces a minor risk of SSRF or other network-related vulnerabilities if not handled securely.

In conclusion, the plugin is in a relatively secure state, with its lack of known vulnerabilities and proper SQL handling being significant strengths. The primary weakness lies in the incomplete output escaping, which, despite the absence of current taint findings, represents a notable risk that should be addressed to improve the plugin's overall security.

Key Concerns

  • Incomplete output escaping
  • External HTTP requests present
Vulnerabilities
None known

EV Crosswords Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

EV Crosswords Release Timeline

v2.0.7Current
v2.0.6
v2.0.5
v2.0.4
v2.0.3
v2.0.2
v2.0.1
v2.0.0
Code Analysis
Analyzed Mar 17, 2026

EV Crosswords Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
20
41 escaped
Nonce Checks
1
Capability Checks
6
File Operations
0
External Requests
3
Bundled Libraries
0

Output Escaping

67% escaped61 total outputs
Attack Surface

EV Crosswords Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_evcw_creatorive_api_key_ajax_controllerbackend\config\EvCwPluginSettings.php:27
WordPress Hooks 11
actionadmin_initbackend\config\EvCwPluginSettings.php:20
actionadmin_menubackend\config\EvCwPluginSettings.php:24
actionadmin_enqueue_scriptsbackend\config\EvCwPluginSettings.php:26
actionrest_api_initbackend\controller\EvCwRestController.php:20
actioninitbackend\service\EvCwPluginLauncher.php:25
filterplugin_action_linksbackend\service\EvCwPluginLauncher.php:26
filterplugin_row_metabackend\service\EvCwPluginLauncher.php:27
actionwp_enqueue_scriptsbackend\service\EvCwPluginLauncher.php:45
actionwp_headbackend\service\EvCwPluginLauncher.php:46
actionadmin_initbackend\service\EvCwPluginLauncher.php:48
actionadmin_menubackend\service\EvCwPluginLauncher.php:52
Maintenance & Trust

EV Crosswords Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedApr 12, 2026
PHP min version8.1
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

EV Crosswords Developer Profile

Entreveloper

2 plugins · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect EV Crosswords

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ev-crosswords/backend/js/admin.js/wp-content/plugins/ev-crosswords/backend/css/admin.css
Script Paths
/wp-content/plugins/ev-crosswords/backend/js/admin.js
Version Parameters
ev-crosswords/backend/css/admin.css?ver=ev-crosswords/backend/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
evcw_rowevcw_ai_local_provider_url_wrap
HTML Comments
AI Config callback function.AI Provider callback function.
Data Attributes
data-custom
JS Globals
MyPluginSettings
REST Endpoints
/wp-json/ev-crosswords/v1/ai/settings
Shortcode Output
[ev-crossword]
FAQ

Frequently Asked Questions about EV Crosswords