
Horoscope Feeder Security & Risk Analysis
wordpress.org/plugins/horoscope-feederHoroscope Feeder is a plugin that displays your horoscope for the day, which after installation, you can use the widget or shortcode.
Is Horoscope Feeder Safe to Use in 2026?
Generally Safe
Score 85/100Horoscope Feeder has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The horoscope-feeder plugin v1.0.1 presents a mixed security posture. On the positive side, it exhibits strong adherence to secure coding practices regarding SQL queries, utilizing prepared statements exclusively. The absence of external HTTP requests and file operations further reduces its attack surface. However, several areas raise concerns. The use of the `create_function` is a significant red flag, as it can be leveraged for code injection if not handled with extreme care, though its current usage in this plugin doesn't appear to be directly exposed to user input based on the static analysis. More importantly, a considerable portion of output (47%) is not properly escaped, leaving it vulnerable to Cross-Site Scripting (XSS) attacks if any of the data displayed originates from user input or untrusted sources. The plugin also completely lacks nonce checks and capability checks, meaning that its single shortcode entry point, and any potential future additions, are not protected against CSRF or unauthorized access.
Key Concerns
- Use of create_function
- Significant amount of unescaped output
- Missing nonce checks
- Missing capability checks
Horoscope Feeder Security Vulnerabilities
Horoscope Feeder Code Analysis
Dangerous Functions Found
Output Escaping
Horoscope Feeder Attack Surface
Shortcodes 1
WordPress Hooks 8
Maintenance & Trust
Horoscope Feeder Maintenance & Trust
Maintenance Signals
Community Trust
Horoscope Feeder Alternatives
The Daily Horoscope
the-daily-horoscope
Add The Daily Horoscope Plugin to your widgets, posts and pages. Select your sign and read your daily horoscope.
Divine Astro
horoscope-and-tarot
Divineapi.com is a leading API platform for services like Daily Horoscope, Tarot reading, Kundali, Panchang, Natal Chart, Fortune Cookie, Coffee Cup r …
Daily Fortune Telling Cards
daily-fortune-telling-cards
Official Daily Fortune Telling Cards plugin, supported by the PowerFortunes team. Fortune Telling Cards adds value and interesting content to your sit …
viversum: Mondphase
viversum-mondphase
viversum Mondphase als Widget
Weekly Fortune Telling Cards
weekly-fortune-telling-cards
Official Weekly Fortune Telling Cards plugin, supported by the PowerFortunes team. Fortune Telling Cards adds value and interesting content to your si …
Horoscope Feeder Developer Profile
1 plugin · 10 total installs
How We Detect Horoscope Feeder
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/horoscope-feeder/css/style.css/wp-content/plugins/horoscope-feeder/js/scripts.js/wp-content/plugins/horoscope-feeder/css/colorpicker.css/wp-content/plugins/horoscope-feeder/js/scripts.jshoroscope-feeder/css/style.css?ver=horoscope-feeder/js/scripts.js?ver=HTML / DOM Fingerprints
horoscope-feeder-widgetdata-aligndata-widthdata-countdata-show-datedata-show-descdata-show-author+15 morewindow.horoscope_scripts[horoscope-feeder]