
Level system Security & Risk Analysis
wordpress.org/plugins/level-systemRequires PHP: 5.2.4 License: GPLv2 or later License URI: https://www.gnu.org/licenses/gpl-2.0.html The one and only level system for wordpress.
Is Level system Safe to Use in 2026?
Generally Safe
Score 100/100Level system has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "level-system" plugin v1.0.2 exhibits a concerning security posture despite the absence of known vulnerabilities and a seemingly small attack surface. The static analysis reveals critical weaknesses, particularly the presence of the `create_function` construct, which is widely deprecated due to its potential for arbitrary code execution. Furthermore, all SQL queries are executed without prepared statements, leaving them vulnerable to SQL injection attacks. The low percentage of properly escaped output (31%) indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities across various output points. The taint analysis showing flows with unsanitized paths, even without critical or high severity, is a strong indicator that user-supplied data is not being adequately validated or sanitized before use, which can lead to exploitable conditions if combined with other weaknesses. While the plugin has no recorded CVEs, this is likely due to the fundamental flaws in its code rather than its inherent security. The lack of capability checks and nonce checks further exacerbates these risks, allowing unauthenticated or unauthorized users to potentially interact with sensitive functionalities if an attack vector is discovered. In conclusion, the plugin has significant security flaws that outweigh its perceived small attack surface and lack of vulnerability history. Immediate attention is required to address the insecure coding practices identified.
Key Concerns
- Dangerous function: create_function used
- Raw SQL without prepared statements (2/2)
- Low output escaping (31%)
- Taint flows with unsanitized paths (2/2)
- No nonce checks
- No capability checks
Level system Security Vulnerabilities
Level system Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Level system Attack Surface
WordPress Hooks 12
Maintenance & Trust
Level system Maintenance & Trust
Maintenance Signals
Community Trust
Level system Alternatives
Social LikeBox & Feed
facebook-by-weblizar
Display your FaceBook Feed and Like box on your website with this outstanding plugin. It is completely customizable, responsive and the code is search …
Widget Responsive for Youtube
youtube-widget-responsive
Widgets + ShortCode responsive to embed youtube in your sidebar or in your content [youtube video=...] or in WPBakery Page Builder, with SEO http://sc …
Ultimate Addons for SiteOrigin
addon-so-widgets-bundle
An ultimate collection of addons for SiteOrigin. SiteOrigin Widgets Bundle is required.
Easy Sidebar Menu Widget
easy-sidebar-menu-widget
Add WordPress Dropdown Menu Widget easily! Upgrade your sidebar menus to responsive dropdown widget now!
Flex Posts – Widget and Gutenberg Block
flex-posts
A widget to display posts with thumbnails in various layouts. Fits nicely in any widget area size.
Level system Developer Profile
1 plugin · 0 total installs
How We Detect Level system
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/level-system/css/level_system-admin.css/wp-content/plugins/level-system/js/level_system-admin.js/wp-content/plugins/level-system/js/level_system-admin.jslevel_system-admin.css?ver=level_system-admin.js?ver=HTML / DOM Fingerprints
progress-bardata-plugin-name="Level_system"data-plugin-version="1.0.2"window.level_system_admin_params