
Football Predictor Security & Risk Analysis
wordpress.org/plugins/football-predictorTo manage and perform a marvel football competition for the FIFA World Cup 2018.
Is Football Predictor Safe to Use in 2026?
Generally Safe
Score 100/100Football Predictor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "football-predictor" v1.0.9 plugin exhibits a concerning security posture despite a clean vulnerability history. The static analysis reveals significant weaknesses, particularly in its handling of user input and access control. The presence of an unprotected AJAX handler is a major red flag, providing an easily accessible entry point for attackers. Compounding this, the taint analysis shows a high number of flows with unsanitized paths, with 12 classified as high severity. This strongly suggests potential for code injection or data manipulation vulnerabilities, especially when combined with the unprotected AJAX handler.
While the plugin demonstrates good practices in using prepared statements for the majority of its SQL queries and has a robust number of nonce checks, these strengths are overshadowed by the identified weaknesses. The lack of proper output escaping on a substantial portion of its outputs also presents a risk for cross-site scripting (XSS) vulnerabilities. The absence of any recorded vulnerabilities in its history is positive, but it should not lead to complacency, as the static analysis clearly indicates latent risks that could be exploited. Overall, this plugin requires immediate attention to address the unprotected entry points and unsanitized data flows to mitigate significant security risks.
Key Concerns
- Unprotected AJAX handler found
- High severity taint flows identified
- Low percentage of properly escaped output
- Unserialize function used
Football Predictor Security Vulnerabilities
Football Predictor Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Football Predictor Attack Surface
AJAX Handlers 1
WordPress Hooks 10
Maintenance & Trust
Football Predictor Maintenance & Trust
Maintenance Signals
Community Trust
Football Predictor Alternatives
Euro 2012 Predictor
euro-2012-predictor
Plugin to manage and present a fantasy football (soccer) competition for the UEFA 2012 Euro Championships
Prediction League
prediction-league
Self hosted prediction league for your blog
AnWP Football Leagues
football-leagues-by-anwppro
A complete solution for any football site. Knockout and round-robin competitions, player profiles and statistics, squads, standings and stadiums.
Football Pool
football-pool
Add some game-day fun to your WordPress site! Let users predict match results, earn points, and go head-to-head in a fantasy sports pool.
Soccer Widgets – Football Results & Rankings
webeki-soccer-scores
Soccer Widgets: use shortcodes to deliver updated soccer data like various table rankings and football results by competition.
Football Predictor Developer Profile
1 plugin · 10 total installs
How We Detect Football Predictor
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/football-predictor/admin/css/fp-admin.css/wp-content/plugins/football-predictor/admin/js/fp-admin.js/wp-content/plugins/football-predictor/assets/css/fp-frontend.css/wp-content/plugins/football-predictor/assets/js/fp-frontend.js/wp-content/plugins/football-predictor/admin/js/fp-admin.js/wp-content/plugins/football-predictor/assets/js/fp-frontend.jsfootball-predictor/admin/css/fp-admin.css?ver=football-predictor/admin/js/fp-admin.js?ver=football-predictor/assets/css/fp-frontend.css?ver=football-predictor/assets/js/fp-frontend.js?ver=HTML / DOM Fingerprints
fp_groupfp_knockoutfp_prediction_deadline<!-- FOOTBALL PREDICTOR START --><!-- FOOTBALL PREDICTOR END --><!-- FOOTBALL PREDICTOR SHORTCODE START --><!-- FOOTBALL PREDICTOR SHORTCODE END -->data-fp-user-iddata-fp-match-iddata-fp-home-goalsdata-fp-away-goalsdata-fp-home-penaltiesdata-fp-away-penalties+3 morefp_localize[football_predictor_frontend][football_predictor_stats][football_predictor_groups][football_predictor_knockout]