
EZ Horoscope Professional Security & Risk Analysis
wordpress.org/plugins/ez-horoscopeAstrologically accurate horoscopes with cosmic insights, advice, birth charts, and AI voice agents for chatting about readings.
Is EZ Horoscope Professional Safe to Use in 2026?
Generally Safe
Score 100/100EZ Horoscope Professional has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "ez-horoscope" plugin v2.2.2.43 exhibits a generally good security posture with strong output escaping and SQL prepared statement usage. The absence of critical code signals like dangerous functions and file operations, coupled with no recorded vulnerability history, are positive indicators. However, the presence of 10 unprotected entry points, specifically 2 AJAX handlers and 8 REST API routes without permission callbacks, represents a significant area of concern. These unprotected endpoints could potentially be exploited by unauthenticated users, leading to unauthorized actions or information disclosure.
The static analysis reveals a moderate attack surface with a substantial number of unprotected entry points. While taint analysis shows no issues, this is likely due to a lack of flows being analyzed rather than an absence of potential vulnerabilities. The bundled Freemius library at version 1.0 also warrants attention, as outdated bundled libraries can sometimes introduce their own vulnerabilities if not maintained.
In conclusion, while the plugin demonstrates good coding practices in areas like output sanitization and SQL handling, the unprotected entry points are a critical weakness. The lack of historical vulnerabilities is a positive sign but does not negate the current identified risks. Addressing the unprotected AJAX handlers and REST API routes should be the highest priority for securing this plugin.
Key Concerns
- AJAX handlers without auth checks
- REST API routes without permission callbacks
- Bundled outdated Freemius v1.0 library
EZ Horoscope Professional Security Vulnerabilities
EZ Horoscope Professional Release Timeline
EZ Horoscope Professional Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
EZ Horoscope Professional Attack Surface
AJAX Handlers 5
REST API Routes 8
Shortcodes 12
WordPress Hooks 59
Maintenance & Trust
EZ Horoscope Professional Maintenance & Trust
Maintenance Signals
Community Trust
EZ Horoscope Professional Alternatives
Tarot and Horoscope
tarot-and-horoscope
Add interactive tarot card games and live chat to your WordPress site for free, powered by TarotandHoroscope.com.
Astro API By Synilogic
synilogic-jyotisham-astro
Astro API By Synilogic connects your site to JyotishamAstro to deliver Kundli, Matching, Panchang and Numerology via simple shortcodes.
Dakidarts Numerology Core
dakidarts-numerology-core
Integrate numerology calculations into WordPress with shortcodes, Gutenberg blocks, and customizable forms using the Dakidarts Numerology API.
Divine Astro
horoscope-and-tarot
Divineapi.com is a leading API platform for services like Daily Horoscope, Tarot reading, Kundali, Panchang, Natal Chart, Fortune Cookie, Coffee Cup r …
The Daily Horoscope
the-daily-horoscope
Add The Daily Horoscope Plugin to your widgets, posts and pages. Select your sign and read your daily horoscope.
EZ Horoscope Professional Developer Profile
1 plugin · 200 total installs
How We Detect EZ Horoscope Professional
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ez-horoscope/css/horoscope.css/wp-content/plugins/ez-horoscope/js/horoscope.js/wp-content/plugins/ez-horoscope/css/ezhp-admin.css/wp-content/plugins/ez-horoscope/js/voice-agent.js/wp-content/plugins/ez-horoscope/js/horoscope.js/wp-content/plugins/ez-horoscope/js/voice-agent.jsez-horoscope/css/horoscope.css?ver=ez-horoscope/js/horoscope.js?ver=ez-horoscope/css/ezhp-admin.css?ver=ez-horoscope/js/voice-agent.js?ver=HTML / DOM Fingerprints
ezhp-horoscope-widgetezhp-tarot-card<!-- EZ Horoscope Start --><!-- EZ Horoscope End --><!-- EZ Horoscope Widget --><!-- EZ Horoscope Tarot 3 Card Spread -->data-ezhp-iddata-ezhp-horoscope-iddata-ezhp-zodiac-signdata-ezhp-tarot-idezhpAjaxezhpVoiceAgentezhp_globals/wp-json/ezhoroscope/v1/get_horoscope/wp-json/ezhoroscope/v1/get_zodiac_compatibility/wp-json/ezhoroscope/v1/get_chinese_horoscope/wp-json/ezhoroscope/v1/get_numerology/wp-json/ezhoroscope/v1/get_birth_chart/wp-json/ezhoroscope/v1/get_synastry_chart/wp-json/ezhoroscope/v1/get_moon_phase/wp-json/ezhoroscope/v1/get_horoscope_summaries[ezhp_ezhoroscope][ezhp_ezweeklyhoroscope][ezhp_eznumerology][ezhp_ezsunsigncompatibility]