lgv-anmeldesystem Security & Risk Analysis

wordpress.org/plugins/lgv-anmeldesystem

The "lgv-anmeldesystem is a registration tool, where people can register itself and optional modify or delete the registration at a later time by …

10 active installs v1.23 PHP 5.2.4+ WP 4.6+ Updated Jan 1, 2026
anmeldungregistration
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is lgv-anmeldesystem Safe to Use in 2026?

Generally Safe

Score 100/100

lgv-anmeldesystem has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The lgv-anmeldesystem plugin v1.23 exhibits a generally good security posture with several strengths. The extensive use of prepared statements for all SQL queries and a high percentage of properly escaped output demonstrate a commitment to fundamental security practices. Furthermore, the plugin's attack surface is limited, with no identified AJAX handlers or REST API routes lacking authentication or permission checks. The absence of any recorded vulnerabilities or CVEs in its history is also a positive indicator. However, a notable concern is the presence of the `unserialize` function, which, if not handled with extreme caution and robust input validation, can lead to serious security vulnerabilities like Remote Code Execution. While the taint analysis did not flag critical or high severity issues, the identification of flows with unsanitized paths warrants further investigation, as this could indicate potential weaknesses that haven't yet manifested as critical vulnerabilities or been discovered. The presence of a nonce check and capability checks indicates some awareness of security measures, but their limited count relative to the plugin's functionality and entry points could be a concern.

Key Concerns

  • Dangerous function unserialize found
  • 3 flows with unsanitized paths
  • 1 file operation identified
  • Limited number of nonce and capability checks
Vulnerabilities
None known

lgv-anmeldesystem Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

lgv-anmeldesystem Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
21 prepared
Unescaped Output
30
265 escaped
Nonce Checks
1
Capability Checks
2
File Operations
1
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

unserialize$newObj = unserialize(serialize($this));includes\class-lgv-as-bo-event.php:485

SQL Query Safety

100% prepared21 total queries

Output Escaping

90% escaped295 total outputs
Data Flows
3 unsanitized

Data Flow Analysis

4 flows3 with unsanitized paths
display_event (includes\class-lgv-as-backend.php:244)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

lgv-anmeldesystem Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[lgv_anmeldesystem] includes\class-lgv-as-frontend.php:12
[lgv-anmeldesystem] includes\class-lgv-as-frontend.php:13
WordPress Hooks 5
actionadmin_menuincludes\class-lgv-as-backend.php:13
actionplugins_loadedincludes\class-lgv-as-backend.php:14
actionplugins_loadedincludes\class-lgv-as-db.php:28
actionadmin_noticesincludes\class-lgv-as-db.php:96
actionwp_enqueue_scriptsincludes\class-lgv-as-frontend.php:15
Maintenance & Trust

lgv-anmeldesystem Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 1, 2026
PHP min version5.2.4
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

lgv-anmeldesystem Developer Profile

jkalmbach

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect lgv-anmeldesystem

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/lgv-anmeldesystem/includes/styles.css/wp-content/plugins/lgv-anmeldesystem/includes/scripts.js
Script Paths
/wp-content/plugins/lgv-anmeldesystem/includes/scripts.js
Version Parameters
lgv-anmeldesystem/includes/styles.css?ver=lgv-anmeldesystem/includes/scripts.js?ver=

HTML / DOM Fingerprints

CSS Classes
lgvas_validation_error
HTML Comments
2015-01-08: Vorerst wird die automatische Nachruecken deaktiviert, da man lieber selber das Nachruecken Steuerung und priorisieren will!
Data Attributes
data-lgvas_evtid
Shortcode Output
[lgv_anmeldesystem][lgv-anmeldesystem]
FAQ

Frequently Asked Questions about lgv-anmeldesystem