
Launches from SpaceX Security & Risk Analysis
wordpress.org/plugins/launches-from-spacexShow your visitors upcoming and recent SpaceX launches in your sidebar. Uses the r-spacex API: https://github.com/r-spacex/SpaceX-API
Is Launches from SpaceX Safe to Use in 2026?
Generally Safe
Score 85/100Launches from SpaceX has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "launches-from-spacex" plugin, in version 1.0.0, exhibits a mixed security posture. On the positive side, it demonstrates good practices by not exposing any AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, it has no known vulnerabilities (CVEs) and avoids dangerous functions and external HTTP requests. The SQL queries that are present are also correctly prepared, which is a significant strength.
However, several concerning areas are highlighted by the static analysis. The most critical weakness is that 100% of its output is not properly escaped. This opens the door to potential Cross-Site Scripting (XSS) vulnerabilities if any of the plugin's outputs are derived from user-controlled input. The single file operation also represents a potential entry point for file manipulation vulnerabilities if not handled securely. The absence of nonce and capability checks on any potential, albeit currently non-existent, entry points is also a notable gap.
Given the lack of historical vulnerabilities, it's difficult to draw strong conclusions about past security practices beyond the current version. The strengths lie in the limited attack surface and secure database interactions. The primary weakness is the pervasive lack of output escaping, which, despite the current limited attack surface, poses a significant risk of XSS if the plugin's functionality were to expand or if user input is processed in any way that is not immediately obvious from this static analysis. Overall, while the current plugin has a small footprint, the unescaped output requires immediate attention.
Key Concerns
- 0% properly escaped output
- 1 file operation without explicit checks
- 0 Nonce checks present
- 0 Capability checks present
Launches from SpaceX Security Vulnerabilities
Launches from SpaceX Release Timeline
Launches from SpaceX Code Analysis
Output Escaping
Launches from SpaceX Attack Surface
WordPress Hooks 2
Maintenance & Trust
Launches from SpaceX Maintenance & Trust
Maintenance Signals
Community Trust
Launches from SpaceX Alternatives
NASA Picture of the Day
nasa-astrology-picture-of-the-day
Allow your readers to enjoy NASA's Astronomy Picture of the Day on your blog with this easy to use and setup plugin.
Imsanity
imsanity
Automatically resizes huge image uploads. Are contributors uploading huge photos? Tired of manually resizing your images? Imsanity to the rescue!
PNG to JPG
png-to-jpg
Convert PNG images to JPG, free up web space and speed up your webpage
Disk Usage Sunburst
disk-usage-sunburst
Visualize and drill down the disk usage of your whole WordPress installation. Find and identify big files immediately!
My Simple Space
my-simple-space
Disk Space, Database and Memory Usage in the dashboard.
Launches from SpaceX Developer Profile
2 plugins · 10 total installs
How We Detect Launches from SpaceX
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/launches-from-spacex/assets/css/spacex-launches.css