
EV Crosswords Security & Risk Analysis
wordpress.org/plugins/ev-crosswordsEasily add crosswords to your Wordpress website, with or without AI help.
Is EV Crosswords Safe to Use in 2026?
Generally Safe
Score 100/100EV Crosswords has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'ev-crosswords' plugin version 2.0.5 exhibits a generally good security posture based on the provided static analysis and vulnerability history. The absence of any recorded CVEs, along with the fact that all identified SQL queries use prepared statements, indicates strong development practices in these areas. The plugin also implements capability checks for its entry points and has a low overall attack surface with no directly unprotected entry points found.
However, there are a few areas that warrant attention. The 67% output escaping rate means that nearly a third of all output operations are not properly escaped, potentially leading to cross-site scripting (XSS) vulnerabilities. While no specific taint flows were identified, this lack of complete output escaping significantly increases the risk of XSS if user-supplied data is involved in any of the unescaped outputs. The presence of external HTTP requests also introduces a minor risk of SSRF or other network-related vulnerabilities if not handled securely.
In conclusion, the plugin is in a relatively secure state, with its lack of known vulnerabilities and proper SQL handling being significant strengths. The primary weakness lies in the incomplete output escaping, which, despite the absence of current taint findings, represents a notable risk that should be addressed to improve the plugin's overall security.
Key Concerns
- Incomplete output escaping
- External HTTP requests present
EV Crosswords Security Vulnerabilities
EV Crosswords Release Timeline
EV Crosswords Code Analysis
Output Escaping
EV Crosswords Attack Surface
AJAX Handlers 1
WordPress Hooks 11
Maintenance & Trust
EV Crosswords Maintenance & Trust
Maintenance Signals
Community Trust
EV Crosswords Alternatives
Funbutler Booking System
funbutler-booking
This plugin is used to connect with Funbutler Booking system.
Sudoku – The Game
sudoku-game
Let your website visitors play the famous sudoku game.
AMG Labs Minesweeper Game
amglabs-minesweeper-game
A classic Windows-style Minesweeper game for WordPress. Relive the nostalgia of the iconic puzzle game directly on your website.
Devarai Crosswords
devarai-crosswords
The world's best crossword puzzles from the world's leading crossword authors on your website for free.
Latest Apple Movie Trailers
latest-apple-movie-trailers
Displays the latest movie trailers featured on Apple.com via the RSS Feed.
EV Crosswords Developer Profile
2 plugins · 10 total installs
How We Detect EV Crosswords
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ev-crosswords/backend/js/admin.js/wp-content/plugins/ev-crosswords/backend/css/admin.css/wp-content/plugins/ev-crosswords/backend/js/admin.jsev-crosswords/backend/css/admin.css?ver=ev-crosswords/backend/js/admin.js?ver=HTML / DOM Fingerprints
evcw_rowevcw_ai_local_provider_url_wrapAI Config callback function.AI Provider callback function.data-customMyPluginSettings/wp-json/ev-crosswords/v1/ai/settings[ev-crossword]