Magic the Gathering Card Tooltips Security & Risk Analysis

wordpress.org/plugins/magic-the-gathering-card-tooltips

Easily transform Magic the Gathering card names into links that show the card image in a tooltip when hovering over them. You can also quickly create …

100 active installs v3.8.0 PHP + WP 2.8.6+ Updated Dec 24, 2025
ccgdeckboxmagic-the-gatheringmtgtcg
98
A · Safe
CVEs total2
Unpatched0
Last CVEFeb 14, 2025
Safety Verdict

Is Magic the Gathering Card Tooltips Safe to Use in 2026?

Generally Safe

Score 98/100

Magic the Gathering Card Tooltips has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Feb 14, 2025Updated 3mo ago
Risk Assessment

The static analysis of "magic-the-gathering-card-tooltips" v3.8.0 reveals a generally positive security posture. The plugin demonstrates good practices by utilizing prepared statements for all SQL queries, implementing nonce checks, and performing capability checks on entry points. There are no identified dangerous functions, file operations, or external HTTP requests, and the attack surface, while present through shortcodes, appears to be well-protected from unauthenticated access. The limited number of flows analyzed by the taint analysis and the absence of unsanitized paths are also encouraging signs.

However, there are areas for improvement. The 83% rate of output escaping, while good, suggests a potential for cross-site scripting (XSS) vulnerabilities in the remaining 17% of outputs. The plugin's vulnerability history, featuring two known CVEs, one of which was high severity (XSS), indicates a past tendency towards input neutralization issues. Although all previous vulnerabilities are currently patched, this history warrants continued vigilance.

In conclusion, "magic-the-gathering-card-tooltips" v3.8.0 has a decent security foundation with robust data handling and access control. The primary concern lies in the potential for XSS due to incomplete output escaping and the historical precedent for such vulnerabilities. Ongoing monitoring and thorough code reviews, particularly around output handling, are recommended to maintain a strong security posture.

Key Concerns

  • Output escaping is not fully implemented
  • Past vulnerabilities including XSS
Vulnerabilities
2

Magic the Gathering Card Tooltips Security Vulnerabilities

CVEs by Year

2 CVEs in 2025
2025
Patched Has unpatched

Severity Breakdown

High
1
Medium
1

2 total CVEs

CVE-2025-26756high · 7.2Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Magic the Gathering Card Tooltips <= 3.5.0 - Unauthenticated Stored Cross-Site Scripting

Feb 14, 2025 Patched in 3.6.0 (13d)
CVE-2025-24704medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Magic the Gathering Card Tooltips <= 3.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

Jan 24, 2025 Patched in 3.5.0 (5d)
Code Analysis
Analyzed Mar 16, 2026

Magic the Gathering Card Tooltips Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
10 escaped
Nonce Checks
1
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

TinyMCE

Output Escaping

83% escaped12 total outputs
Attack Surface

Magic the Gathering Card Tooltips Attack Surface

Entry Points6
Unprotected0

Shortcodes 6

[mtg_card] wp_deckbox_mtg.php:64
[card] wp_deckbox_mtg.php:65
[c] wp_deckbox_mtg.php:66
[mtg_deck] wp_deckbox_mtg.php:67
[deck] wp_deckbox_mtg.php:68
[d] wp_deckbox_mtg.php:69
WordPress Hooks 5
actioninitwp_deckbox_mtg.php:14
actionadmin_menuwp_deckbox_mtg.php:52
filtermce_external_pluginswp_deckbox_mtg.php:78
filtermce_buttonswp_deckbox_mtg.php:79
actionwp_headwp_deckbox_mtg.php:96
Maintenance & Trust

Magic the Gathering Card Tooltips Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 24, 2025
PHP min version
Downloads12K

Community Trust

Rating84/100
Number of ratings6
Active installs100
Developer Profile

Magic the Gathering Card Tooltips Developer Profile

grimdonkey

1 plugin · 100 total installs

93
trust score
Avg Security Score
98/100
Avg Patch Time
9 days
View full developer profile
Detection Fingerprints

How We Detect Magic the Gathering Card Tooltips

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/magic-the-gathering-card-tooltips/resources/css/wp_deckbox_mtg.css/wp-content/plugins/magic-the-gathering-card-tooltips/resources/tooltip_extension.js
Script Paths
https://deckbox.org/javascripts/tooltip.js

HTML / DOM Fingerprints

CSS Classes
deckbox_linkmtg_deckmtg_deck_title
Data Attributes
deckbox
JS Globals
deckbox_extensions
Shortcode Output
[mtg_card][card][c][mtg_deck]
FAQ

Frequently Asked Questions about Magic the Gathering Card Tooltips