FFC Football CO2 Calculator Plugin Security & Risk Analysis

wordpress.org/plugins/ffc-football-co2-calculator

FFC Football CO2 Calculator is a plugin for calculating CO2-emissions in terms of football related CO2 emissions.

0 active installs v3.3 PHP + WP 5.7+ Updated Jul 7, 2025
calculatorco2emissionfootball
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is FFC Football CO2 Calculator Plugin Safe to Use in 2026?

Generally Safe

Score 100/100

FFC Football CO2 Calculator Plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10mo ago
Risk Assessment

The "ffc-football-co2-calculator" v3.3 plugin exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, a commitment to prepared statements for all SQL queries, and proper output escaping are commendable practices. The plugin also avoids external HTTP requests and file operations, further reducing its attack surface. Furthermore, the vulnerability history shows a clean record with no recorded CVEs, indicating a history of secure development or prompt patching.

While the static analysis indicates a robust codebase with no immediate threats like critical taint flows or raw SQL queries, the complete absence of nonce checks and capability checks across all entry points presents a significant concern. Even with a limited attack surface of only two shortcodes, the lack of authorization checks means any user, including unauthenticated ones, could potentially interact with these shortcodes in ways that might be unintended or exploitable if the shortcode logic itself were to have a vulnerability discovered later. The taint analysis also shows zero flows, which is good, but it's worth noting that a zero count here could be due to the analysis methodology or a very simple plugin structure rather than an absolute guarantee of no vulnerabilities.

In conclusion, the plugin demonstrates excellent foundational security practices in its code. However, the lack of any authentication or authorization checks on its entry points is a notable weakness. This oversight, coupled with the minimal attack surface, suggests that while the current code appears safe, it is not resilient against potential future vulnerabilities that might be introduced through its shortcodes if not adequately protected. The clean vulnerability history is a positive sign, but it's crucial to address the authorization gaps to maintain this strong security record.

Key Concerns

  • Missing nonce checks on entry points
  • Missing capability checks on entry points
Vulnerabilities
None known

FFC Football CO2 Calculator Plugin Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

FFC Football CO2 Calculator Plugin Release Timeline

v3.2
v3.1
v3.0
v2.9
v2.8
v2.7
v2.6
v2.4
v2.3
v2.2
v2.1
v2.0
v1.9
v1.8
v1.7
v1.6
v1.5
v1.4
v1.3
v1.2
Code Analysis
Analyzed Apr 16, 2026

FFC Football CO2 Calculator Plugin Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

FFC Football CO2 Calculator Plugin Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[co2calculator] 2.5/init/plugin.php:51
[co2calculator] init/plugin.php:51
WordPress Hooks 6
actioninit2.5/init/plugin.php:30
actioninit2.5/init/plugin.php:31
actionwp_enqueue_scripts2.5/init/plugin.php:33
actioninitinit/plugin.php:30
actioninitinit/plugin.php:31
actionwp_enqueue_scriptsinit/plugin.php:33
Maintenance & Trust

FFC Football CO2 Calculator Plugin Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJul 7, 2025
PHP min version
Downloads7K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

FFC Football CO2 Calculator Plugin Developer Profile

Michael Vogel

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect FFC Football CO2 Calculator Plugin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ffc-football-co2-calculator/css/ffcfcc.css
Script Paths
/wp-content/plugins/ffc-football-co2-calculator/js/ffcfcc.js
Version Parameters
ffcfcc-js-plugin

HTML / DOM Fingerprints

Shortcode Output
[co2calculator]
FAQ

Frequently Asked Questions about FFC Football CO2 Calculator Plugin