
JRM Killboard Security & Risk Analysis
wordpress.org/plugins/jrm-killboardDisplay corporation kills using Killmails: sync it manually or automatically. Customizable: display your killboard the way you like it
Is JRM Killboard Safe to Use in 2026?
Generally Safe
Score 85/100JRM Killboard has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The jrm-killboard plugin v1.3.1 presents a mixed security posture. On the positive side, it demonstrates good practices by using prepared statements for all SQL queries and has no recorded vulnerability history, which suggests a generally secure development approach and a lack of known exploitable flaws.
However, there are notable concerns identified in the static analysis. The plugin exposes a significant attack surface with 18 AJAX handlers, and a concerning 3 of these lack authentication checks. This means that without proper authorization, unauthenticated users could potentially interact with these handlers, leading to unexpected behavior or unintended data manipulation if not otherwise secured. The low percentage of properly escaped output (27%) is another significant weakness, increasing the risk of cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled carefully before being displayed.
While the taint analysis found no critical or high severity issues and the vulnerability history is clean, the presence of unprotected AJAX endpoints and inadequate output escaping are tangible risks that require attention. The lack of capability checks on AJAX handlers further compounds this risk. The plugin's strengths lie in its SQL handling and historical security, but the identified weaknesses in authentication and output sanitization detract from its overall security.
Key Concerns
- AJAX handlers without auth checks
- Low percentage of properly escaped output
- Dangerous function: preg_replace(/e)
- No capability checks on AJAX handlers
JRM Killboard Security Vulnerabilities
JRM Killboard Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
JRM Killboard Attack Surface
AJAX Handlers 18
WordPress Hooks 9
Scheduled Events 3
Maintenance & Trust
JRM Killboard Maintenance & Trust
Maintenance Signals
Community Trust
JRM Killboard Alternatives
Memory Game (Memorama)
memory-game
Captura las imagenes de tu juego de memoria y utiliza el shortcode para el juego [memorygame] y muestralo a tus visitantes Capture images from your me …
QuadMenu – Twenty Seventeen Mega Menu
quadmenu-twentyseventeen-integration
Integrates QuadMenu with the Twenty Seventeen theme. Requires QuadMenu and Twenty Seventeen.
Eve Online Pheal API
eve-online-pheal-api
Do Eve Online related API calls through PHP. Easy to use and fast.
WP Upcoming Releases
wp-upcoming-releases
Show a list of upcoming releases: movies, games, events or any other thing your needs. Easy management with post type and categories.
The Events Calendar
the-events-calendar
The Events Calendar: #1 calendar plugin for WordPress. Create/manage events (virtual too!) on your site with the free plugin.
JRM Killboard Developer Profile
1 plugin · 10 total installs
How We Detect JRM Killboard
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/jrm-killboard/admin/css/jrm-killboard-admin.css/wp-content/plugins/jrm-killboard/admin/css/jrm-killboard-graphic.css/wp-content/plugins/jrm-killboard/admin/css/jrm-killboard-settings.css/wp-content/plugins/jrm-killboard/admin/js/jrm-killboard-admin.js/wp-content/plugins/jrm-killboard/admin/js/jrm-killboard-graphics.js/wp-content/plugins/jrm-killboard/admin/js/jrm-killboard-items.js/wp-content/plugins/jrm-killboard/admin/js/jrm-killboard-settings.js/wp-content/plugins/jrm-killboard/css/jrm-killboard-frontend.css/wp-content/plugins/jrm-killboard/admin/js/jrm-killboard-admin.js/wp-content/plugins/jrm-killboard/admin/js/jrm-killboard-graphics.js/wp-content/plugins/jrm-killboard/admin/js/jrm-killboard-items.js/wp-content/plugins/jrm-killboard/admin/js/jrm-killboard-settings.jsjrm-killboard/admin/css/jrm-killboard-admin.css?ver=jrm-killboard/admin/css/jrm-killboard-graphic.css?ver=jrm-killboard/admin/css/jrm-killboard-settings.css?ver=jrm-killboard/admin/js/jrm-killboard-admin.js?ver=jrm-killboard/admin/js/jrm-killboard-graphics.js?ver=jrm-killboard/admin/js/jrm-killboard-items.js?ver=jrm-killboard/admin/js/jrm-killboard-settings.js?ver=jrm-killboard/css/jrm-killboard-frontend.css?ver=HTML / DOM Fingerprints
jrm-killboard-admin-wrapjrm-killboard-graphic-wrapjrm-killboard-settings-wrapjrm-killboard-items-wrapFly safe Capsuler!data-jrm-killboard-idjrm_killboard_admin_object/wp-json/jrm-killboard/v1/data[jrm_killboard]