
Live Scores for SportsPress Security & Risk Analysis
wordpress.org/plugins/live-scores-for-sportspressAdd Live Scores feature to SportsPress. Give your visitors the ability to view the results without refreshing your page.
Is Live Scores for SportsPress Safe to Use in 2026?
Mostly Safe
Score 84/100Live Scores for SportsPress is generally safe to use though it hasn't been updated recently. 2 past CVEs were resolved. Keep it updated.
The 'live-scores-for-sportspress' plugin v1.9.2 exhibits a concerning security posture due to several factors. While it has a moderate number of entry points, the presence of three unprotected AJAX handlers significantly increases the attack surface. The static analysis also reveals a complete lack of prepared statements for SQL queries, which is a critical vulnerability that can lead to SQL injection. Furthermore, a low percentage of properly escaped output suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities. The vulnerability history, including two past CVEs (one high and one medium severity), reinforces these concerns, highlighting a pattern of 'PHP Remote File Inclusion' and 'Cross-site Scripting' which are serious security flaws. Although there are no currently unpatched vulnerabilities and the taint analysis did not reveal critical or high severity flows, the combination of unprotected entry points, unescaped output, raw SQL queries, and historical vulnerabilities indicates a need for significant improvement in the plugin's security practices.
Key Concerns
- Unprotected AJAX handlers (3)
- 0% SQL prepared statements
- Low output escaping (24%)
- 1 High severity CVE (past)
- 1 Medium severity CVE (past)
- Bundled outdated Freemius v1.0
Live Scores for SportsPress Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Live Scores for SportsPress <= 1.9.0 - Authenticated (Admin+) Local File Inclusion
Live Scores for SportsPress <= 1.9.0 - Reflected Cross-Site Scripting
Live Scores for SportsPress Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Live Scores for SportsPress Attack Surface
AJAX Handlers 10
Shortcodes 1
WordPress Hooks 36
Maintenance & Trust
Live Scores for SportsPress Maintenance & Trust
Maintenance Signals
Community Trust
Live Scores for SportsPress Alternatives
Better Search Replace
better-search-replace
A simple plugin to update URLs or other text in a database.
WP Mail Logging
wp-mail-logging
Log, view, and resend all emails sent from your WordPress site. Great for resolving email sending issues or keeping a copy for auditing.
Instant Indexing for Google
fast-indexing-api
A very efficient yet simple plugin to take care of your indexing woos and helps get your content crawled by search bots instantly.
HubSpot All-In-One Marketing – Forms, Popups, Live Chat
leadin
The CRM, Sales, and Marketing WordPress plugin to grow your business better. Capture and engage web visitors with free live chat, forms, CRM, email ma …
SiteOrigin CSS
so-css
Powerful, simple CSS editing for WordPress. Visual controls & real-time previews for effortless site customization.
Live Scores for SportsPress Developer Profile
12 plugins · 2K total installs
How We Detect Live Scores for SportsPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/live-scores-for-sportspress/css/lsfs-style.css/wp-content/plugins/live-scores-for-sportspress/css/lsfs-live-style.css/wp-content/plugins/live-scores-for-sportspress/js/lsfs-live-scores.js/wp-content/plugins/live-scores-for-sportspress/js/lsfs-live-scores.jslive-scores-for-sportspress/css/lsfs-style.css?ver=live-scores-for-sportspress/css/lsfs-live-style.css?ver=live-scores-for-sportspress/js/lsfs-live-scores.js?ver=HTML / DOM Fingerprints
lsfs-live-scores-wraplsfs-live-scores-matchlsfs-live-scores-match-score<!-- Live Scores for SportsPress v1.9.2 --><!-- Live Scores for SportsPress -->data-lsfs-match-iddata-lsfs-team-idLSFS_LIVE_SCORES_AJAX_URL/wp-json/lsfs/v1/live_scores[lsfs_live_scores]