FenShop (gaming shop for minecraft & steam games) Security & Risk Analysis

wordpress.org/plugins/fenshop

Lien vers FenShop - Boutique gaming sur mesure minecraft & steam Link to FenShop - Gaming shop for minecraft & steam games

10 active installs v1.13.2 PHP + WP 3.0.1+ Updated Jun 16, 2017
gamegamingminecraftshopsteam
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is FenShop (gaming shop for minecraft & steam games) Safe to Use in 2026?

Generally Safe

Score 85/100

FenShop (gaming shop for minecraft & steam games) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The "fenshop" v1.13.2 plugin exhibits a generally strong security posture based on the static analysis and vulnerability history. The absence of known CVEs and a lack of identified critical or high-severity vulnerabilities in its history are positive indicators. The code also demonstrates good practices by using prepared statements for all SQL queries. However, several concerns warrant attention. The taint analysis revealed a significant number of flows with unsanitized paths, specifically 4 out of 5 analyzed, indicating a potential for vulnerabilities related to untrusted input. Furthermore, the output escaping is only at 43%, suggesting that a substantial portion of output may not be properly sanitized, increasing the risk of Cross-Site Scripting (XSS) attacks. The plugin also lacks any nonce or capability checks, which are crucial for securing WordPress functionalities, especially for AJAX requests. While the attack surface appears minimal from the provided data, the lack of authentication checks on these non-existent entry points could still be exploited if they were to be introduced in future versions or if the interpretation of "entry points" is limited to specific handlers. In conclusion, while the plugin benefits from a clean vulnerability history and secure database interactions, the identified issues with unsanitized paths, weak output escaping, and missing security checks are significant weaknesses that require immediate remediation to ensure a robust security posture.

Key Concerns

  • Flows with unsanitized paths
  • Output escaping is low
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

FenShop (gaming shop for minecraft & steam games) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

FenShop (gaming shop for minecraft & steam games) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
3 escaped
Nonce Checks
0
Capability Checks
0
File Operations
5
External Requests
0
Bundled Libraries
0

Output Escaping

43% escaped7 total outputs
Data Flows
4 unsanitized

Data Flow Analysis

5 flows4 with unsanitized paths
login_register (FenShop.php:64)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

FenShop (gaming shop for minecraft & steam games) Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
filterthe_contentFenShop.php:24
filterauthenticateFenShop.php:26
actionuser_registerFenShop.php:27
actionregister_formFenShop.php:28
actiontemplate_redirectFenShop.php:29
actionadmin_menuFenShop.php:694
actionadmin_initFenShop.php:695
Maintenance & Trust

FenShop (gaming shop for minecraft & steam games) Maintenance & Trust

Maintenance Signals

WordPress version tested4.8.28
Last updatedJun 16, 2017
PHP min version
Downloads3K

Community Trust

Rating20/100
Number of ratings1
Active installs10
Developer Profile

FenShop (gaming shop for minecraft & steam games) Developer Profile

fensoft

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect FenShop (gaming shop for minecraft & steam games)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/fenshop/lib/fensession.php/wp-content/plugins/fenshop/lib/fenshop.php

HTML / DOM Fingerprints

HTML Comments
<!--{FenShop:history_begin:}--><!--{FenShop:history_end]-->
REST Endpoints
/api/auth/register//api/auth/authenticate/
Shortcode Output
[FenShop:nick][FenShop:tokens][FenShop:currency][FenShop:history:name]
FAQ

Frequently Asked Questions about FenShop (gaming shop for minecraft & steam games)