
Divine Astro Security & Risk Analysis
wordpress.org/plugins/horoscope-and-tarotDivineapi.com is a leading API platform for services like Daily Horoscope, Tarot reading, Kundali, Panchang, Natal Chart, Fortune Cookie, Coffee Cup r …
Is Divine Astro Safe to Use in 2026?
Generally Safe
Score 91/100Divine Astro has a strong security track record. Known vulnerabilities have been patched promptly.
The horoscope-and-tarot plugin, version 1.3.2, exhibits a mixed security posture. While it demonstrates good practices in handling SQL queries with prepared statements and avoids file operations and cron events, several significant concerns warrant attention. The presence of two unprotected AJAX handlers significantly expands the attack surface, potentially allowing unauthorized actions. Furthermore, the static analysis reveals the use of dangerous functions like 'unserialize' and a low percentage of properly escaped outputs, indicating a higher risk of cross-site scripting (XSS) vulnerabilities.
Key Concerns
- Unprotected AJAX handlers
- Dangerous function usage (unserialize)
- Low percentage of properly escaped output
- No nonce checks on AJAX handlers
- No capability checks
- Bundled outdated library (Select2)
- Bundled outdated library (Guzzle)
Divine Astro Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Horoscope And Tarot <= 1.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
Divine Astro Code Analysis
Dangerous Functions Found
Bundled Libraries
Output Escaping
Divine Astro Attack Surface
AJAX Handlers 2
Shortcodes 51
WordPress Hooks 36
Maintenance & Trust
Divine Astro Maintenance & Trust
Maintenance Signals
Community Trust
Divine Astro Alternatives
EZ Horoscope Professional
ez-horoscope
Astrologically accurate horoscopes with cosmic insights, advice, birth charts, and AI voice agents for chatting about readings.
The Daily Horoscope
the-daily-horoscope
Add The Daily Horoscope Plugin to your widgets, posts and pages. Select your sign and read your daily horoscope.
Tarot and Horoscope
tarot-and-horoscope
Add interactive tarot card games and live chat to your WordPress site for free, powered by TarotandHoroscope.com.
Daily Fortune Telling Cards
daily-fortune-telling-cards
Official Daily Fortune Telling Cards plugin, supported by the PowerFortunes team. Fortune Telling Cards adds value and interesting content to your sit …
Horoscope Feeder
horoscope-feeder
Horoscope Feeder is a plugin that displays your horoscope for the day, which after installation, you can use the widget or shortcode.
Divine Astro Developer Profile
1 plugin · 100 total installs
How We Detect Divine Astro
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/horoscope-and-tarot/public/css/style.css/wp-content/plugins/horoscope-and-tarot/public/js/script.js/wp-content/plugins/horoscope-and-tarot/admin/css/dhat-admin.css/wp-content/plugins/horoscope-and-tarot/admin/js/dhat-admin.js/wp-content/plugins/horoscope-and-tarot/inc/settings/css/settings.css/wp-content/plugins/horoscope-and-tarot/inc/settings/js/settings.js/wp-content/plugins/horoscope-and-tarot/inc/shortcodes/css/shortcodes.css/wp-content/plugins/horoscope-and-tarot/inc/shortcodes/js/shortcodes.js/wp-content/plugins/horoscope-and-tarot/public/js/script.js/wp-content/plugins/horoscope-and-tarot/admin/js/dhat-admin.js/wp-content/plugins/horoscope-and-tarot/inc/settings/js/settings.js/wp-content/plugins/horoscope-and-tarot/inc/shortcodes/js/shortcodes.jshoroscope-and-tarot/public/css/style.css?ver=horoscope-and-tarot/public/js/script.js?ver=horoscope-and-tarot/admin/css/dhat-admin.css?ver=horoscope-and-tarot/admin/js/dhat-admin.js?ver=horoscope-and-tarot/inc/settings/css/settings.css?ver=horoscope-and-tarot/inc/settings/js/settings.js?ver=horoscope-and-tarot/inc/shortcodes/css/shortcodes.css?ver=horoscope-and-tarot/inc/shortcodes/js/shortcodes.js?ver=HTML / DOM Fingerprints
dhat-admin-wrapdhat-settings-formdhat-shortcode-containerInclude admin.phpInclude public.phpInclude Settings PageInclude Shortcodes+1 moredata-plugin-pathdata-plugin-urldhat_plugin_pathdhat_plugin_url[horoscope][daily_horoscope][monthly_horoscope][yearly_horoscope]