Sport livescores: foootball and basketball results, fixtures and standings Security & Risk Analysis

wordpress.org/plugins/football-standings

Add auto-updated live scores information about more than 3000 football and basketball tournaments and standings with ease!

100 active installs v1.0.1 PHP + WP 4.1+ Updated Sep 2, 2024
basketballfootballsportsteamtournaments
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Sport livescores: foootball and basketball results, fixtures and standings Safe to Use in 2026?

Generally Safe

Score 92/100

Sport livescores: foootball and basketball results, fixtures and standings has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "football-standings" plugin, at version 1.0.1, exhibits a strong security posture based on the provided static analysis. All identified SQL queries are properly prepared, and all output is correctly escaped, indicating good development practices regarding common web vulnerabilities. The absence of external HTTP requests and dangerous functions further strengthens its security. The plugin also presents a minimal attack surface with only one shortcode and no identified AJAX handlers, REST API routes, or cron events without proper checks. The lack of any recorded vulnerabilities in its history further reinforces this positive assessment.

However, a significant concern arises from the complete absence of nonce checks and capability checks. While the static analysis did not identify any AJAX handlers or REST API routes that *require* these checks due to their limited number, their complete omission means that if any such entry points were to be added in future versions without these safeguards, they would be immediately vulnerable. Similarly, the single shortcode, while currently not identified as an entry point requiring authentication or authorization checks, could become a risk if it were to handle sensitive data or actions in the future without proper access controls. The presence of file operations without explicit mention of sanitization or access controls also warrants a cautious approach.

In conclusion, the "football-standings" plugin demonstrates a commendable commitment to secure coding practices, particularly in SQL and output handling, and has a clean vulnerability history. The primary weakness lies in the complete lack of nonce and capability checks, which represents a potential future risk if the plugin's functionality expands. The file operation also introduces a minor point of concern that might benefit from further scrutiny.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
  • File operations without explicit sanitization/checks
Vulnerabilities
None known

Sport livescores: foootball and basketball results, fixtures and standings Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Sport livescores: foootball and basketball results, fixtures and standings Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
66 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped66 total outputs
Attack Surface

Sport livescores: foootball and basketball results, fixtures and standings Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[777score] football-standings.php:33
WordPress Hooks 3
actionadmin_menusrc\Score777_ThemeOptions.php:52
actionadmin_initsrc\Score777_ThemeOptions.php:55
actionadmin_enqueue_scriptssrc\Score777_ThemeOptions.php:58
Maintenance & Trust

Sport livescores: foootball and basketball results, fixtures and standings Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedSep 2, 2024
PHP min version
Downloads9K

Community Trust

Rating0/100
Number of ratings0
Active installs100
Developer Profile

Sport livescores: foootball and basketball results, fixtures and standings Developer Profile

footstandings

1 plugin · 100 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Sport livescores: foootball and basketball results, fixtures and standings

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/football-standings/assets/styles.css/wp-content/plugins/football-standings/assets/jquery.custom.js
Script Paths
/wp-content/plugins/football-standings/assets/jquery.custom.js
Version Parameters
football-standings/assets/styles.css?ver=football-standings/assets/jquery.custom.js?ver=

HTML / DOM Fingerprints

CSS Classes
cfg777
Data Attributes
data-o_namedata-def_colordata-def
Shortcode Output
[777score][777score path=/live][777score path=/football/tournaments/england/premier-league][777score path=/football/tournaments/england/premier-league/results]
FAQ

Frequently Asked Questions about Sport livescores: foootball and basketball results, fixtures and standings