FA Sport Odds Security & Risk Analysis

wordpress.org/plugins/fa-sport-odds

Create an odds betslip from our feed with all sports and leagues available. Automatic signup to track your revenue from start.

10 active installs v1.1 PHP + WP 3.6+ Updated Jun 28, 2016
affiliatebettingeuro2016oddssoccer
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is FA Sport Odds Safe to Use in 2026?

Generally Safe

Score 85/100

FA Sport Odds has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The "fa-sport-odds" v1.1 plugin exhibits a mixed security posture. On the positive side, it utilizes prepared statements for all SQL queries and has a clean vulnerability history with no known CVEs. The absence of external HTTP requests and bundled libraries is also a strength. However, significant concerns arise from the static analysis. A substantial attack surface is exposed with two AJAX handlers, neither of which includes authentication checks, representing a direct path for unauthenticated attackers. Furthermore, only 17% of output operations are properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. The taint analysis reveals four flows with unsanitized paths, though thankfully these did not escalate to critical or high severity issues in this analysis. The lack of capability checks on entry points further exacerbates the risk of unauthorized actions.

Key Concerns

  • AJAX handlers without auth checks
  • Low percentage of properly escaped output
  • Unsanitized paths in taint analysis
  • No capability checks on entry points
Vulnerabilities
None known

FA Sport Odds Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

FA Sport Odds Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
118
24 escaped
Nonce Checks
4
Capability Checks
0
File Operations
18
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

17% escaped142 total outputs
Data Flows
4 unsanitized

Data Flow Analysis

5 flows4 with unsanitized paths
RegistrationPage (fa-sport-odds-views.php:9)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

FA Sport Odds Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_fa_sportodds_getleaguesfa-sport-odds.php:59
authwp_ajax_fa_sport_odds_not_registered_noticefa-sport-odds.php:62
WordPress Hooks 8
actionadmin_menufa-sport-odds.php:48
actionadmin_menufa-sport-odds.php:49
actionadmin_noticesfa-sport-odds.php:55
actionwidgets_initfa-sport-odds.php:58
actionwp_enqueue_scriptsfa-sport-odds.php:60
actionadmin_enqueue_scriptsfa-sport-odds.php:61
actionfa-sportodds-scheduled_check_applicationfa-sport-odds.php:63
actionsetup_themefa-sport-odds.php:416

Scheduled Events 1

fa-sportodds-scheduled_check_application
Maintenance & Trust

FA Sport Odds Maintenance & Trust

Maintenance Signals

WordPress version tested4.5.33
Last updatedJun 28, 2016
PHP min version
Downloads6K

Community Trust

Rating90/100
Number of ratings4
Active installs10
Developer Profile

FA Sport Odds Developer Profile

Betfinal

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect FA Sport Odds

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/fa-sport-odds/fa-sportodds.css/wp-content/plugins/fa-sport-odds/fa-sportodds.js/wp-content/plugins/fa-sport-odds/dateformat.js/wp-content/plugins/fa-sport-odds/fa-sportodds-admin.js
Script Paths
fa-sportodds-admin.jsfa-sportodds.jsdateformat.js
Version Parameters
fa-sportodds-admin.js?ver=fa-sportodds.css?ver=fa-sportodds.js?ver=dateformat.js?ver=

HTML / DOM Fingerprints

CSS Classes
fa-sport-odds
Data Attributes
data-fa-sport-odds-widget-id
JS Globals
fa_sport_odds_admin_paramsfa_sportodds_options
Shortcode Output
[fa_sport_odds]
FAQ

Frequently Asked Questions about FA Sport Odds