
Funny fruits Security & Risk Analysis
wordpress.org/plugins/funny-fruitsThis is a simple game where you have 90 seconds to score as many points as possible.
Is Funny fruits Safe to Use in 2026?
Generally Safe
Score 85/100Funny fruits has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "funny-fruits" v1.0 plugin exhibits a mixed security posture. On the positive side, the static analysis reveals no dangerous functions, SQL queries are exclusively handled with prepared statements, and there are no file operations or external HTTP requests, which significantly reduces common attack vectors. Furthermore, the vulnerability history shows no previously recorded CVEs, suggesting a potentially well-maintained codebase. However, several significant concerns arise from the code signals. A substantial 17% of output is not properly escaped, posing a risk of Cross-Site Scripting (XSS) vulnerabilities. Additionally, the complete absence of nonce checks and capability checks on its sole entry point (a shortcode) leaves it vulnerable to various forms of injection and unauthorized execution if the shortcode's functionality is not inherently safe. Taint analysis shows no flows, which is good, but this may be due to a limited scope of analysis or a very simple plugin with limited user input processing. The lack of authentication checks on any entry points, even though the attack surface is small, is a notable weakness. Overall, while the plugin avoids some common pitfalls, the unescaped output and the lack of proper authentication/authorization on its shortcode present tangible security risks that should be addressed.
Key Concerns
- Unescaped output detected
- No nonce checks on entry points
- No capability checks on entry points
Funny fruits Security Vulnerabilities
Funny fruits Release Timeline
Funny fruits Code Analysis
Output Escaping
Funny fruits Attack Surface
Shortcodes 1
WordPress Hooks 1
Maintenance & Trust
Funny fruits Maintenance & Trust
Maintenance Signals
Community Trust
Funny fruits Alternatives
Magic Food
magic-food
This is a simple game where you have a short time to remove each item of food.
Travel Game – Vacation Widget
travel-game
Try to hit the hottest destination and plan vacation early with a recreational travel game. Display the game in your website in seconds with a simple …
WP Recipe Maker
wp-recipe-maker
The easy and user-friendly recipe plugin for everyone. Automatic JSON-LD metadata for food AND how-to recipes will improve your SEO!
WP Menu Icons
wp-menu-icons
WP Menu Icons allows you to add icons to your WordPress menu items.
MAS Static Content
mas-static-content
MAS Static Content is a free plugin that allows you to to create a custom post type static content and use it with shortcode.
Funny fruits Developer Profile
8 plugins · 130 total installs
How We Detect Funny fruits
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/funny-fruits/funnyfruits.phpHTML / DOM Fingerprints
[funnyfruits]