
Football Odds Security & Risk Analysis
wordpress.org/plugins/football-oddsFootball Odds WP create on your pages / site (via shortcode) a complete football odds comparison system.
Is Football Odds Safe to Use in 2026?
Generally Safe
Score 85/100Football Odds has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "football-odds" v1.9 plugin exhibits a mixed security posture. On the positive side, it has a very small attack surface with only one shortcode and no AJAX handlers or REST API routes exposed without authentication. The vulnerability history is clean, with no known CVEs, suggesting a generally stable development process. However, the static analysis reveals significant areas of concern. The prevalence of SQL queries, with only 15% using prepared statements, is a substantial risk, potentially leading to SQL injection vulnerabilities. Similarly, a low rate of proper output escaping (57%) raises concerns about Cross-Site Scripting (XSS) vulnerabilities. The taint analysis highlights two flows with unsanitized paths, which, although not classified as critical, represent a high severity risk of code execution or data leakage.
While the lack of historical vulnerabilities is a strong positive, the static analysis flags point to potential weaknesses that could be exploited if not addressed. The high number of raw SQL queries and the moderate rate of unescaped output are common vectors for serious security breaches. The presence of two high-severity taint flows, even without a "critical" classification, demands immediate attention. The plugin's strengths lie in its limited attack surface and clean CVE history, but the internal code quality, particularly around data handling and output, presents a notable risk that requires remediation.
Key Concerns
- High percentage of SQL queries not using prepared statements
- Moderate percentage of outputs not properly escaped
- Two high severity taint flows with unsanitized paths
- No capability checks on entry points
Football Odds Security Vulnerabilities
Football Odds Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Football Odds Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
Football Odds Maintenance & Trust
Maintenance Signals
Community Trust
Football Odds Alternatives
AnWP Football Leagues
football-leagues-by-anwppro
A complete solution for any football site. Knockout and round-robin competitions, player profiles and statistics, squads, standings and stadiums.
Soccer Widgets – Football Results & Rankings
webeki-soccer-scores
Soccer Widgets: use shortcodes to deliver updated soccer data like various table rankings and football results by competition.
Soccer Engine – Soccer Plugin for WordPress
soccer-engine-lite
Soccer Engine is a plugin that lets bloggers and clubs add results, fixtures, match commentaries, transfers, and a wide range of stats to articles.
StatsFC Table
statsfc-table
This widget will place a football league table on your website.
StatsFC Fixtures
statsfc-fixtures
This widget will display a list of football fixtures on your website, for a chosen competition or team.
Football Odds Developer Profile
1 plugin · 10 total installs
How We Detect Football Odds
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/football-odds/css/fodds.css/wp-content/plugins/football-odds/js/jscolor.js/wp-content/plugins/football-odds/js/jscolor.jsfootball-odds/css/fodds.css?ver=football-odds/js/jscolor.js?ver=HTML / DOM Fingerprints
window.jscolor[fodds]