
Magic the Gathering Card Tooltips Security & Risk Analysis
wordpress.org/plugins/magic-the-gathering-card-tooltipsEasily transform Magic the Gathering card names into links that show the card image in a tooltip when hovering over them. You can also quickly create …
Is Magic the Gathering Card Tooltips Safe to Use in 2026?
Generally Safe
Score 98/100Magic the Gathering Card Tooltips has a strong security track record. Known vulnerabilities have been patched promptly.
The static analysis of "magic-the-gathering-card-tooltips" v3.8.0 reveals a generally positive security posture. The plugin demonstrates good practices by utilizing prepared statements for all SQL queries, implementing nonce checks, and performing capability checks on entry points. There are no identified dangerous functions, file operations, or external HTTP requests, and the attack surface, while present through shortcodes, appears to be well-protected from unauthenticated access. The limited number of flows analyzed by the taint analysis and the absence of unsanitized paths are also encouraging signs.
However, there are areas for improvement. The 83% rate of output escaping, while good, suggests a potential for cross-site scripting (XSS) vulnerabilities in the remaining 17% of outputs. The plugin's vulnerability history, featuring two known CVEs, one of which was high severity (XSS), indicates a past tendency towards input neutralization issues. Although all previous vulnerabilities are currently patched, this history warrants continued vigilance.
In conclusion, "magic-the-gathering-card-tooltips" v3.8.0 has a decent security foundation with robust data handling and access control. The primary concern lies in the potential for XSS due to incomplete output escaping and the historical precedent for such vulnerabilities. Ongoing monitoring and thorough code reviews, particularly around output handling, are recommended to maintain a strong security posture.
Key Concerns
- Output escaping is not fully implemented
- Past vulnerabilities including XSS
Magic the Gathering Card Tooltips Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Magic the Gathering Card Tooltips <= 3.5.0 - Unauthenticated Stored Cross-Site Scripting
Magic the Gathering Card Tooltips <= 3.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
Magic the Gathering Card Tooltips Code Analysis
Bundled Libraries
Output Escaping
Magic the Gathering Card Tooltips Attack Surface
Shortcodes 6
WordPress Hooks 5
Maintenance & Trust
Magic the Gathering Card Tooltips Maintenance & Trust
Maintenance Signals
Community Trust
Magic the Gathering Card Tooltips Alternatives
MTGPulse deckbox embedding tool
mtgpulse-magic-the-gathering-deckbox-plugin
Facilitates embedding of MTGPulse.com deckboxes on your word press site
MtG-Tutor.de CardLinker
mtg-tutorde-cardlinker
This plugin provides some shortcode to easily link MtG Cards and Decks! - Ein Plugin mit dem man ganz leicht MtG Karten und Decks verlinken kann!
CCG Manager
ccg-manager
A WordPress plugin to manage your CCG collection
TCG Card Links
tcg-card-links
The goal of this Plug-in is to provide an instantaneous way for you to turn all Magic: the Gathering card names within your blog posts into card infor …
WP MtG-Helper
wp-mtg-helper
The goal of this plugin is to help you writing articels about Magic: the Gathering like tournament reports or draft walkthroughs and reducing the time …
Magic the Gathering Card Tooltips Developer Profile
1 plugin · 100 total installs
How We Detect Magic the Gathering Card Tooltips
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/magic-the-gathering-card-tooltips/resources/css/wp_deckbox_mtg.css/wp-content/plugins/magic-the-gathering-card-tooltips/resources/tooltip_extension.jshttps://deckbox.org/javascripts/tooltip.jsHTML / DOM Fingerprints
deckbox_linkmtg_deckmtg_deck_titledeckboxdeckbox_extensions[mtg_card][card][c][mtg_deck]