Golf Handicap & Slope Security & Risk Analysis

wordpress.org/plugins/golf-handicap-slope

An advanced calculator for golfers that calculates playing handicap based on Slope Rating, Course Rating and Par. Perfect for golf clubs.

10 active installs v2.1.8 PHP 7.0+ WP 5.6+ Updated Mar 27, 2026
calculatorgolfhandicapslopewhs
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Golf Handicap & Slope Safe to Use in 2026?

Generally Safe

Score 100/100

Golf Handicap & Slope has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "golf-handicap-slope" plugin, version 2.1.5, demonstrates several strong security practices, including a high percentage of SQL queries using prepared statements and near-perfect output escaping. The plugin also implements nonce and capability checks on its entry points, which is commendable. There are no known historical vulnerabilities, suggesting a generally well-maintained codebase.

However, the static analysis reveals a significant concern: all 8 analyzed taint flows have unsanitized paths, with 8 classified as high severity. This indicates that user-supplied data is not being properly validated or sanitized before being used in potentially dangerous operations, even though direct dangerous function usage is reported as zero. This could lead to unexpected behavior or security exploits if these unsanitized paths are indeed exploitable.

While the plugin has a clean vulnerability history, the high number of high-severity unsanitized taint flows is a critical flag. The absence of direct vulnerabilities historically might be due to luck or a lack of targeted auditing. The overall security posture is mixed, with excellent foundational security practices contrasted by a concerning pattern of potentially insecure data handling within its internal flows.

Key Concerns

  • High severity unsanitized taint flows (8)
  • All analyzed taint flows are unsanitized
Vulnerabilities
None known

Golf Handicap & Slope Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Golf Handicap & Slope Release Timeline

v2.1.8Current
v2.1.5
v2.1.4
v2.1.3
Code Analysis
Analyzed Mar 17, 2026

Golf Handicap & Slope Code Analysis

Dangerous Functions
0
Raw SQL Queries
5
21 prepared
Unescaped Output
2
150 escaped
Nonce Checks
10
Capability Checks
8
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

81% prepared26 total queries

Output Escaping

99% escaped152 total outputs
Data Flows · Security
8 unsanitized

Data Flow Analysis

8 flows8 with unsanitized paths
render_tee_management_page (includes\class-golf-handicap-slope-admin.php:160)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Golf Handicap & Slope Attack Surface

Entry Points10
Unprotected0

AJAX Handlers 8

authwp_ajax_golfhs_add_teeincludes\class-golf-handicap-slope-admin.php:38
authwp_ajax_golfhs_update_teeincludes\class-golf-handicap-slope-admin.php:39
authwp_ajax_golfhs_delete_teeincludes\class-golf-handicap-slope-admin.php:40
authwp_ajax_golfhs_move_tee_upincludes\class-golf-handicap-slope-admin.php:41
authwp_ajax_golfhs_move_tee_downincludes\class-golf-handicap-slope-admin.php:42
authwp_ajax_golfhs_update_tee_orderincludes\class-golf-handicap-slope-admin.php:43
authwp_ajax_golfhs_get_teesincludes\class-golf-handicap-slope-shortcodes.php:36
noprivwp_ajax_golfhs_get_teesincludes\class-golf-handicap-slope-shortcodes.php:37

Shortcodes 2

[golfhs_calculator] includes\class-golf-handicap-slope-shortcodes.php:32
[golfhs_tables] includes\class-golf-handicap-slope-shortcodes.php:33
WordPress Hooks 14
actioninitgolf-handicap-slope.php:144
actionwp_enqueue_scriptsgolf-handicap-slope.php:193
actionwp_enqueue_scriptsgolf-handicap-slope.php:237
actionadmin_menuincludes\class-golf-handicap-slope-admin.php:32
actionadmin_enqueue_scriptsincludes\class-golf-handicap-slope-admin.php:35
actionadmin_post_golfhs_move_tee_upincludes\class-golf-handicap-slope-admin.php:46
actionadmin_post_golfhs_move_tee_downincludes\class-golf-handicap-slope-admin.php:47
actionadmin_menuincludes\class-golf-handicap-slope-settings.php:53
actionadmin_initincludes\class-golf-handicap-slope-settings.php:56
actionadmin_enqueue_scriptsincludes\class-golf-handicap-slope-settings.php:59
actionwp_enqueue_scriptsincludes\class-golf-handicap-slope-settings.php:62
actionadmin_enqueue_scriptsincludes\class-golf-handicap-slope-settings.php:65
actionadmin_enqueue_scriptsincludes\class-golf-handicap-slope-settings.php:68
actionwp_enqueue_scriptsincludes\enqueue-styles.php:86
Maintenance & Trust

Golf Handicap & Slope Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 27, 2026
PHP min version7.0
Downloads377

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Golf Handicap & Slope Developer Profile

Gudjon Gudjonsson

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Golf Handicap & Slope

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/golf-handicap-slope/css/golf-handicap-slope.css/wp-content/plugins/golf-handicap-slope/js/golf-handicap-slope.js
Script Paths
/wp-content/plugins/golf-handicap-slope/js/golf-handicap-slope.js
Version Parameters
golf-handicap-slope/css/golf-handicap-slope.css?ver=golf-handicap-slope/js/golf-handicap-slope.js?ver=

HTML / DOM Fingerprints

CSS Classes
golf-handicap-slope-formgolfhs-calculatorgolfhs-tee-selectgolfhs-gender-selectgolfhs-handicap-inputgolfhs-calculate-buttongolfhs-resultgolfhs-input-group
HTML Comments
<!-- START GOLF HANDICAP & SLOPE CALCULATOR --><!-- END GOLF HANDICAP & SLOPE CALCULATOR -->
Data Attributes
data-golfhs-nonce
JS Globals
golfhs_datagolfhs_i18n
Shortcode Output
[golf_handicap_calculator]
FAQ

Frequently Asked Questions about Golf Handicap & Slope