List the S&P 500 Constituents Financials Security & Risk Analysis

wordpress.org/plugins/list-sp-500-constituents-financials

The plugin display the list of S&P 500 companies.

10 active installs v1.3 PHP + WP 5.3+ Updated Aug 24, 2023
investments-and-p-500sp500sharesstocks
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is List the S&P 500 Constituents Financials Safe to Use in 2026?

Generally Safe

Score 85/100

List the S&P 500 Constituents Financials has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The 'list-sp-500-constituents-financials' v1.3 plugin exhibits a generally good security posture based on the static analysis. There are no identified critical or high severity taint flows, and the plugin does not make external HTTP requests, which is positive. The number of identified SQL queries is moderate, and a reasonable percentage are using prepared statements, mitigating some SQL injection risks. Output escaping is applied to a majority of outputs, and nonce checks are present, indicating an awareness of common WordPress vulnerabilities. The absence of any known CVEs further strengthens this positive outlook.

However, there are a few areas that warrant attention. While the attack surface appears small and no entry points are explicitly unprotected, the limited number of capability checks (only 1) could be a concern if the unprotected AJAX handler or shortcode performs sensitive operations. Additionally, the SQL query implementation is not fully robust, with 80% of queries not using prepared statements, leaving a potential for SQL injection vulnerabilities if not handled with extreme care. The presence of file operations also presents a theoretical risk if not implemented with strict sanitization and validation, though no specific issues were flagged in the taint analysis.

Overall, the plugin demonstrates a commitment to security best practices, particularly in avoiding external requests and implementing some core security checks. The vulnerability history being clean is a strong indicator of past security diligence. The primary areas for improvement lie in strengthening SQL query sanitization and ensuring proper capability checks for all sensitive operations, even if the attack surface appears limited and currently unexploved.

Key Concerns

  • SQL queries not using prepared statements
  • Output escaping not fully comprehensive
  • Limited capability checks on entry points
Vulnerabilities
None known

List the S&P 500 Constituents Financials Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

List the S&P 500 Constituents Financials Release Timeline

v1.3Current
v1.2
v1.1
v1.0
Code Analysis
Analyzed Mar 17, 2026

List the S&P 500 Constituents Financials Code Analysis

Dangerous Functions
0
Raw SQL Queries
4
1 prepared
Unescaped Output
31
49 escaped
Nonce Checks
2
Capability Checks
1
File Operations
3
External Requests
0
Bundled Libraries
0

SQL Query Safety

20% prepared5 total queries

Output Escaping

61% escaped80 total outputs
Attack Surface

List the S&P 500 Constituents Financials Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 1

authwp_ajax_mxsapc_updateincludes\admin\models\MXSAPC_Main_Page_Model.php:18

Shortcodes 1

[mx_display_s_and_p_500] includes\frontend\classes\add-shortcodes.php:13
WordPress Hooks 10
actioninitincludes\admin\classes\cpt.php:23
actionadmin_enqueue_scriptsincludes\admin\classes\enqueue-scripts.php:24
actionadmin_enqueue_scriptsincludes\admin\classes\metabox-image-upload.php:15
actionadd_meta_boxesincludes\admin\classes\metabox.php:56
actionsave_postincludes\admin\classes\metabox.php:58
actionadmin_noticesincludes\core\error_handle\Display-Error.php:27
actionadmin_noticesincludes\core\error_handle\Display_Error.php:26
actionadmin_menuincludes\core\Route-Registrar.php:165
actionwp_enqueue_scriptsincludes\frontend\classes\enqueue-scripts.php:24
actionplugins_loadedlist-sp-500-constituents-financials.php:116
Maintenance & Trust

List the S&P 500 Constituents Financials Maintenance & Trust

Maintenance Signals

WordPress version tested6.3.8
Last updatedAug 24, 2023
PHP min version
Downloads8K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

List the S&P 500 Constituents Financials Developer Profile

Maksym Marko

12 plugins · 1K total installs

66
trust score
Avg Security Score
82/100
Avg Patch Time
881 days
View full developer profile
Detection Fingerprints

How We Detect List the S&P 500 Constituents Financials

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/list-sp-500-constituents-financials/assets/font-awesome-4.6.3/css/font-awesome.min.css/wp-content/plugins/list-sp-500-constituents-financials/includes/admin/assets/css/style.css/wp-content/plugins/list-sp-500-constituents-financials/includes/admin/assets/js/script.js/wp-content/plugins/list-sp-500-constituents-financials/includes/admin/assets/js/image-upload.js/wp-content/plugins/list-sp-500-constituents-financials/includes/frontend/assets/css/style.css/wp-content/plugins/list-sp-500-constituents-financials/includes/frontend/assets/css/app.02610d83.css/wp-content/plugins/list-sp-500-constituents-financials/includes/frontend/assets/js/script.js/wp-content/plugins/list-sp-500-constituents-financials/includes/frontend/assets/js/chunk-vendors.94ca894d.js+1 more
Script Paths
/wp-content/plugins/list-sp-500-constituents-financials/includes/admin/assets/js/script.js/wp-content/plugins/list-sp-500-constituents-financials/includes/admin/assets/js/image-upload.js/wp-content/plugins/list-sp-500-constituents-financials/includes/frontend/assets/js/script.js/wp-content/plugins/list-sp-500-constituents-financials/includes/frontend/assets/js/chunk-vendors.94ca894d.js/wp-content/plugins/list-sp-500-constituents-financials/includes/frontend/assets/js/app.ddaa44e9.js
Version Parameters
list-sp-500-constituents-financials/assets/font-awesome-4.6.3/css/font-awesome.min.css?ver=list-sp-500-constituents-financials/includes/admin/assets/css/style.css?ver=list-sp-500-constituents-financials/includes/admin/assets/js/script.js?ver=list-sp-500-constituents-financials/includes/admin/assets/js/image-upload.js?ver=list-sp-500-constituents-financials/includes/frontend/assets/css/style.css?ver=list-sp-500-constituents-financials/includes/frontend/assets/css/app.02610d83.css?ver=list-sp-500-constituents-financials/includes/frontend/assets/js/script.js?ver=list-sp-500-constituents-financials/includes/frontend/assets/js/chunk-vendors.94ca894d.js?ver=list-sp-500-constituents-financials/includes/frontend/assets/js/app.ddaa44e9.js?ver=

HTML / DOM Fingerprints

CSS Classes
s-and-p-500-constituents-financials
HTML Comments
Unique string - MXSAPC Define MXSAPC_PLUGIN_PATH E:\OpenServer\domains\my-domain.com\wp-content\plugins\list-sp-500-constituents-financials\list-sp-500-constituents-financials.php Define MXSAPC_PLUGIN_URL+16 more
JS Globals
mxsapc_admin_localizemxsapc_data_obj_frontmxsapc_option_columns
Shortcode Output
<noscript><strong>We're sorry but list-sp-500-constituents-financials doesn't work properly without JavaScript enabled. Please enable it to continue.</strong></noscript><div id="mx_s_and_p_app" class="s-and-p-500-constituents-financials"></div>
FAQ

Frequently Asked Questions about List the S&P 500 Constituents Financials