
FenShop (gaming shop for minecraft & steam games) Security & Risk Analysis
wordpress.org/plugins/fenshopLien vers FenShop - Boutique gaming sur mesure minecraft & steam Link to FenShop - Gaming shop for minecraft & steam games
Is FenShop (gaming shop for minecraft & steam games) Safe to Use in 2026?
Generally Safe
Score 85/100FenShop (gaming shop for minecraft & steam games) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "fenshop" v1.13.2 plugin exhibits a generally strong security posture based on the static analysis and vulnerability history. The absence of known CVEs and a lack of identified critical or high-severity vulnerabilities in its history are positive indicators. The code also demonstrates good practices by using prepared statements for all SQL queries. However, several concerns warrant attention. The taint analysis revealed a significant number of flows with unsanitized paths, specifically 4 out of 5 analyzed, indicating a potential for vulnerabilities related to untrusted input. Furthermore, the output escaping is only at 43%, suggesting that a substantial portion of output may not be properly sanitized, increasing the risk of Cross-Site Scripting (XSS) attacks. The plugin also lacks any nonce or capability checks, which are crucial for securing WordPress functionalities, especially for AJAX requests. While the attack surface appears minimal from the provided data, the lack of authentication checks on these non-existent entry points could still be exploited if they were to be introduced in future versions or if the interpretation of "entry points" is limited to specific handlers. In conclusion, while the plugin benefits from a clean vulnerability history and secure database interactions, the identified issues with unsanitized paths, weak output escaping, and missing security checks are significant weaknesses that require immediate remediation to ensure a robust security posture.
Key Concerns
- Flows with unsanitized paths
- Output escaping is low
- Missing nonce checks
- Missing capability checks
FenShop (gaming shop for minecraft & steam games) Security Vulnerabilities
FenShop (gaming shop for minecraft & steam games) Code Analysis
Output Escaping
Data Flow Analysis
FenShop (gaming shop for minecraft & steam games) Attack Surface
WordPress Hooks 7
Maintenance & Trust
FenShop (gaming shop for minecraft & steam games) Maintenance & Trust
Maintenance Signals
Community Trust
FenShop (gaming shop for minecraft & steam games) Alternatives
StoreLink for Minecraft by MrDino
storelinkformc
Connect your WooCommerce store with a Minecraft server. Deliver in-game items when an order is completed, using a secure and customizable REST API.
Advanced Steam Widget
advanced-steam-widget
Displays Steam gaming statistics in a widget with increased flexibility, stability, and performance
PoloPag – Pix Automático para eCommerce
wc-polo-payments
Aceite pagamentos via Pix e receba instantaneamente no banco de sua preferência! Instalação e configuração simples para todos.
Meeple Like Us Boardgamegeek Plugin
meeple-like-us-boardgamegeek
Note: This plugin makes use of an external API that is to be found at http://imaginary-realities.com/bggapi/. This is a service hosted via JustHost i …
Manager for Steam
manager-for-steam
Complete Steam integration with visual customization, Gutenberg blocks, and comprehensive Steam Web API support.
FenShop (gaming shop for minecraft & steam games) Developer Profile
1 plugin · 10 total installs
How We Detect FenShop (gaming shop for minecraft & steam games)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/fenshop/lib/fensession.php/wp-content/plugins/fenshop/lib/fenshop.phpHTML / DOM Fingerprints
<!--{FenShop:history_begin:}--><!--{FenShop:history_end]-->/api/auth/register//api/auth/authenticate/[FenShop:nick][FenShop:tokens][FenShop:currency][FenShop:history:name]