Informationsabfrage – Spigotmc Security & Risk Analysis

wordpress.org/plugins/informationsabfrage-spigotmc

Mit diesen Plugin kann man Informationen von einem Plugin abfragen, welches auf spigotmc.org hochgeladen wurde.

0 active installs v1.0 PHP + WP 3.7.0+ Updated Jul 6, 2023
importinformationjsonspigetspigotmc
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Informationsabfrage – Spigotmc Safe to Use in 2026?

Generally Safe

Score 85/100

Informationsabfrage – Spigotmc has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "informationsabfrage-spigotmc" plugin v1.0 demonstrates several good security practices in its static analysis. Notably, it avoids dangerous functions, exclusively uses prepared statements for SQL queries, and has no recorded vulnerability history, indicating a potentially stable and secure codebase. The absence of critical or high severity taint flows and a clean vulnerability record are positive signs. However, significant concerns arise from the lack of output escaping and the complete absence of capability and nonce checks. While the attack surface is primarily through shortcodes, the lack of any authorization checks on these entry points is a critical oversight. This means that any user, regardless of their role or permissions, could potentially trigger the plugin's functionality. The presence of external HTTP requests without apparent validation also poses a risk if not handled securely. The plugin's overall security posture is a mix of strong foundational practices (SQL, no known vulnerabilities) and critical weaknesses (output escaping, authorization).

Given the identified weaknesses, particularly the lack of authorization and output escaping on shortcode entry points, there is a considerable risk of unauthorized actions and potential cross-site scripting (XSS) vulnerabilities. The static analysis indicates that the 5 shortcodes are the primary entry points and none have capability checks. This means that potentially sensitive information could be exposed or actions could be performed by unauthenticated users. The external HTTP requests also represent a potential attack vector if they lead to the execution of unsanitized data or if the plugin is susceptible to SSRF attacks. The vulnerability history being clean is a good sign, but it does not mitigate the risks identified in the current codebase. The plugin needs immediate attention to implement proper authorization and output escaping to secure its entry points.

Key Concerns

  • Missing capability checks on entry points
  • Unescaped output
  • External HTTP requests without apparent checks
  • Missing nonce checks on shortcodes
Vulnerabilities
None known

Informationsabfrage – Spigotmc Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Informationsabfrage – Spigotmc Release Timeline

v1.0Current
Code Analysis
Analyzed Mar 17, 2026

Informationsabfrage – Spigotmc Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
5
Bundled Libraries
0

Output Escaping

0% escaped1 total outputs
Attack Surface

Informationsabfrage – Spigotmc Attack Surface

Entry Points5
Unprotected0

Shortcodes 5

[spmcauthor] spmc-shortcodes.php:4
[spmcversion] spmc-shortcodes.php:5
[spmcupdatetitle] spmc-shortcodes.php:6
[spmcplugindownloads] spmc-shortcodes.php:7
[spmcpluginprice] spmc-shortcodes.php:8
WordPress Hooks 4
actionspmc_languagespmc-main.php:18
actionadmin_menuspmc-main.php:19
actionadmin_initspmc-main.php:34
actionspmc_default_valuesspmc-main.php:73
Maintenance & Trust

Informationsabfrage – Spigotmc Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedJul 6, 2023
PHP min version
Downloads5K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Informationsabfrage – Spigotmc Developer Profile

domisiding

4 plugins · 100 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Informationsabfrage – Spigotmc

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
form_text
Data Attributes
id="spmc-daten"name="spmc_id"
Shortcode Output
[spmcauthor][spmcversion][spmcupdatetitle][spmcplugindownloads]
FAQ

Frequently Asked Questions about Informationsabfrage – Spigotmc