
Magic Food Security & Risk Analysis
wordpress.org/plugins/magic-foodThis is a simple game where you have a short time to remove each item of food.
Is Magic Food Safe to Use in 2026?
Generally Safe
Score 85/100Magic Food has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'magic-food' v5.1 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by having no known vulnerabilities, no dangerous function usage, and all SQL queries utilizing prepared statements. The absence of file operations and external HTTP requests also reduces potential attack vectors. The presence of a nonce check, while only one, is a positive signal for input validation. However, significant concerns arise from the output escaping analysis, where only 1% of 75 outputs are properly escaped. This indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, where user-supplied data could be injected and executed within the browser. Additionally, the lack of capability checks on any entry points, coupled with the presence of a shortcode, suggests that actions triggered by this shortcode may be accessible to users without the necessary permissions, potentially leading to privilege escalation or unauthorized access to plugin functionalities. The plugin's limited attack surface and clean vulnerability history are strengths, but the severe output escaping issues and lack of capability checks present notable security weaknesses.
Key Concerns
- Low percentage of properly escaped output
- Missing capability checks on entry points
Magic Food Security Vulnerabilities
Magic Food Release Timeline
Magic Food Code Analysis
Output Escaping
Magic Food Attack Surface
Shortcodes 1
WordPress Hooks 1
Maintenance & Trust
Magic Food Maintenance & Trust
Maintenance Signals
Community Trust
Magic Food Alternatives
Funny fruits
funny-fruits
This is a simple game where you have 90 seconds to score as many points as possible.
CCG Manager
ccg-manager
A WordPress plugin to manage your CCG collection
Temporary Login Without Password
temporary-login-without-password
Create self-expiring, temporary admin accounts. Easily share direct login links (no need for username/password) with your developers or editors.
ImageMagick Engine
imagemagick-engine
Improve the quality of re-sized images by replacing standard GD library with ImageMagick.
WP Recipe Maker
wp-recipe-maker
The easy and user-friendly recipe plugin for everyone. Automatic JSON-LD metadata for food AND how-to recipes will improve your SEO!
Magic Food Developer Profile
8 plugins · 130 total installs
How We Detect Magic Food
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/magic-food/magicfood_pc.css/wp-content/plugins/magic-food/magicfood_pc.js/wp-content/plugins/magic-food/magicfood_pc.jsmagic-food/magicfood_pc.css?ver=magic-food/magicfood_pc.js?ver=HTML / DOM Fingerprints
oumf-containeroumf-food-itemdata-food-iddata-food-srcdata-food-nameoumfajaxcode<div id="oumf-game-canvas"></div>