Fixture Viewer for PlayHQ Security & Risk Analysis

wordpress.org/plugins/fixture-viewer-for-playhq

Display PlayHQ team fixtures on your WordPress site with a shortcode. Includes team selection and advanced table styling options.

10 active installs v1.5 PHP 7.2+ WP 5.0+ Updated Mar 3, 2026
fixturesplayhqshortcodesportsteams
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Fixture Viewer for PlayHQ Safe to Use in 2026?

Generally Safe

Score 100/100

Fixture Viewer for PlayHQ has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The fixture-viewer-for-playhq plugin, version 1.5, exhibits a generally good security posture with several positive indicators. The absence of known CVEs and a strong adherence to using prepared statements for SQL queries are commendable. Additionally, the plugin demonstrates a high rate of proper output escaping and includes a reasonable number of nonce checks for its entry points.

However, the analysis does reveal a significant concern regarding its attack surface. Specifically, there is one unprotected AJAX handler. This represents a direct entry point for attackers that lacks authentication, potentially allowing for unauthorized actions or data manipulation if not properly secured by the application's surrounding logic.

While the plugin's vulnerability history is clean, suggesting diligent development or a lack of past discovery, the presence of an unprotected AJAX handler remains a critical weakness. The absence of taint analysis data makes it difficult to assess the potential impact of exploiting this handler, but it warrants immediate attention. Overall, the plugin is built on a solid foundation of secure coding practices, but the unprotected AJAX handler poses a notable risk that should be addressed.

Key Concerns

  • Unprotected AJAX handler
Vulnerabilities
None known

Fixture Viewer for PlayHQ Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Fixture Viewer for PlayHQ Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
73 escaped
Nonce Checks
3
Capability Checks
0
File Operations
0
External Requests
3
Bundled Libraries
0

Output Escaping

97% escaped75 total outputs
Attack Surface
1 unprotected

Fixture Viewer for PlayHQ Attack Surface

Entry Points2
Unprotected1

AJAX Handlers 1

authwp_ajax_playhq_get_teamsfixture-viewer-for-playhq.php:968

Shortcodes 1

[playhq_fixtures] fixture-viewer-for-playhq.php:1082
WordPress Hooks 4
actionadmin_menufixture-viewer-for-playhq.php:22
actionadmin_initfixture-viewer-for-playhq.php:274
actionadmin_enqueue_scriptsfixture-viewer-for-playhq.php:277
actionwp_enqueue_scriptsfixture-viewer-for-playhq.php:349
Maintenance & Trust

Fixture Viewer for PlayHQ Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMar 3, 2026
PHP min version7.2
Downloads348

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Fixture Viewer for PlayHQ Developer Profile

markrblackburn

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Fixture Viewer for PlayHQ

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/fixture-viewer-for-playhq/css/style.css/wp-content/plugins/fixture-viewer-for-playhq/js/fixture-viewer.js
Script Paths
/wp-content/plugins/fixture-viewer-for-playhq/js/fixture-viewer.js
Version Parameters
fixture-viewer-for-playhq/css/style.css?ver=fixture-viewer-for-playhq/js/fixture-viewer.js?ver=

HTML / DOM Fingerprints

CSS Classes
playhq-fixtures-tableplayhq-fixtures-headerplayhq-fixtures-rowplayhq-fixtures-cellplayhq-team-selector-containerplayhq-team-selector
HTML Comments
<!-- PlayHQ Fixture Viewer Settings --><!-- Fixture Viewer for PlayHQ Settings Page --><!-- End PlayHQ Fixture Viewer Settings --><!-- Display PlayHQ Fixtures -->
Data Attributes
data-playhq-date-formatdata-playhq-time-formatdata-playhq-team-iddata-playhq-organisation-iddata-playhq-api-keydata-playhq-filter+18 more
JS Globals
window.PlayHQFixtureViewer
Shortcode Output
[playhq_fixtures]
FAQ

Frequently Asked Questions about Fixture Viewer for PlayHQ