
FFC Football CO2 Calculator Plugin Security & Risk Analysis
wordpress.org/plugins/ffc-football-co2-calculatorFFC Football CO2 Calculator is a plugin for calculating CO2-emissions in terms of football related CO2 emissions.
Is FFC Football CO2 Calculator Plugin Safe to Use in 2026?
Generally Safe
Score 100/100FFC Football CO2 Calculator Plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "ffc-football-co2-calculator" v3.3 plugin exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, a commitment to prepared statements for all SQL queries, and proper output escaping are commendable practices. The plugin also avoids external HTTP requests and file operations, further reducing its attack surface. Furthermore, the vulnerability history shows a clean record with no recorded CVEs, indicating a history of secure development or prompt patching.
While the static analysis indicates a robust codebase with no immediate threats like critical taint flows or raw SQL queries, the complete absence of nonce checks and capability checks across all entry points presents a significant concern. Even with a limited attack surface of only two shortcodes, the lack of authorization checks means any user, including unauthenticated ones, could potentially interact with these shortcodes in ways that might be unintended or exploitable if the shortcode logic itself were to have a vulnerability discovered later. The taint analysis also shows zero flows, which is good, but it's worth noting that a zero count here could be due to the analysis methodology or a very simple plugin structure rather than an absolute guarantee of no vulnerabilities.
In conclusion, the plugin demonstrates excellent foundational security practices in its code. However, the lack of any authentication or authorization checks on its entry points is a notable weakness. This oversight, coupled with the minimal attack surface, suggests that while the current code appears safe, it is not resilient against potential future vulnerabilities that might be introduced through its shortcodes if not adequately protected. The clean vulnerability history is a positive sign, but it's crucial to address the authorization gaps to maintain this strong security record.
Key Concerns
- Missing nonce checks on entry points
- Missing capability checks on entry points
FFC Football CO2 Calculator Plugin Security Vulnerabilities
FFC Football CO2 Calculator Plugin Release Timeline
FFC Football CO2 Calculator Plugin Code Analysis
FFC Football CO2 Calculator Plugin Attack Surface
Shortcodes 2
WordPress Hooks 6
Maintenance & Trust
FFC Football CO2 Calculator Plugin Maintenance & Trust
Maintenance Signals
Community Trust
FFC Football CO2 Calculator Plugin Alternatives
Calculated Fields Form
calculated-fields-form
The CFF plugin allows you to create both simple and professional forms. Its form builder includes dynamic calculated fields and many other controls.
Cost Calculator Builder
cost-calculator-builder
WP Cost Calculator is a simple and powerful tool that lets you create price estimation forms. Easily give your clients information about your services …
Cost of Goods: Product Cost & Profit Calculator for WooCommerce
cost-of-goods-for-woocommerce
Unlock detailed insights into products profitability, calculate COGS & profit margins, and get a better financial analytics insights with our Cost …
WPCargo Track & Trace
wpcargo
WPCargo is a track & trace system for courier, courier script, parcel, balikbayan system, shipment and transportation management system, ideal sol …
Responsive Mortgage Calculator
responsive-mortgage-calculator
A simple responsive mortgage calculator widget and shortcode.
FFC Football CO2 Calculator Plugin Developer Profile
1 plugin · 0 total installs
How We Detect FFC Football CO2 Calculator Plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ffc-football-co2-calculator/css/ffcfcc.css/wp-content/plugins/ffc-football-co2-calculator/js/ffcfcc.jsffcfcc-js-pluginHTML / DOM Fingerprints
[co2calculator]