football_game_by_kashanshah Security & Risk Analysis

wordpress.org/plugins/football-game-by-kashan-shah

This is a very simple football game. It may easily be added to any wordpress site to attract the visitors as FIFA Wordl Cup 2018 is just here.

0 active installs v0.0.9 PHP 5.2.4+ WP 4.0.1+ Updated May 24, 2018
body-tagcountry-namesdevelopers
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is football_game_by_kashanshah Safe to Use in 2026?

Generally Safe

Score 85/100

football_game_by_kashanshah has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The "football-game-by-kashan-shah" plugin v0.0.9 demonstrates a generally strong security posture with no recorded vulnerabilities or exploitable code signals like dangerous functions, SQL injection risks, or file operations. The absence of external HTTP requests and bundled libraries further reduces potential attack vectors. However, a significant concern arises from the lack of output escaping for all identified outputs. This means that any data processed by the plugin and then displayed to users or within the WordPress admin area could potentially be vulnerable to Cross-Site Scripting (XSS) attacks if the data originates from an untrusted source. While the current attack surface is small and primarily consists of a single shortcode without explicit authentication or capability checks, this is less of a concern given the lack of other vulnerabilities. The plugin's history of zero CVEs is a positive indicator, but the unescaped output remains a notable weakness that should be addressed to ensure a more robust security.

Key Concerns

  • No output escaping found
  • Shortcode without capability checks
Vulnerabilities
None known

football_game_by_kashanshah Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

football_game_by_kashanshah Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped3 total outputs
Attack Surface

football_game_by_kashanshah Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[football_game_by_kashanshah] football-game-by-kashanshah.php:60
WordPress Hooks 1
actionadmin_menufootball-game-by-kashanshah.php:17
Maintenance & Trust

football_game_by_kashanshah Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedMay 24, 2018
PHP min version5.2.4
Downloads11K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

football_game_by_kashanshah Developer Profile

kashanshah

4 plugins · 60 total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect football_game_by_kashanshah

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/football-game-by-kashan-shah/assets/css/style.css/wp-content/plugins/football-game-by-kashan-shah/assets/js/scripts.js
Version Parameters
football-game-by-kashanshah/assets/js/scripts.js?ver=1.0.0

HTML / DOM Fingerprints

CSS Classes
football-gamefootball-game-containerfootball-game-divgoal-targetleft-top-targetleft-bottom-targetright-top-targetright-bottom-target+2 more
Data Attributes
href="javascript:scoreGoal('LT');"href="javascript:scoreGoal('LB');;"href="javascript:scoreGoal('RT');;"href="javascript:scoreGoal('RB');;"href="javascript:;setArena();"
JS Globals
scoreGoalsetArena
Shortcode Output
<div class="football-game"><div class="football-game-container"><div class="football-game-div"><div class="goal-target">
FAQ

Frequently Asked Questions about football_game_by_kashanshah