
Manager for Steam Security & Risk Analysis
wordpress.org/plugins/manager-for-steamComplete Steam integration with visual customization, Gutenberg blocks, and comprehensive Steam Web API support.
Is Manager for Steam Safe to Use in 2026?
Generally Safe
Score 100/100Manager for Steam has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'manager-for-steam' plugin v2.3.1 exhibits a mixed security posture. While there are no recorded vulnerabilities or dangerous functions, indicating a generally well-maintained codebase, significant concerns arise from its attack surface and data handling practices. A substantial portion of the plugin's AJAX handlers (17 out of 25) lack authentication checks, presenting a direct pathway for unauthorized actions if these handlers are exploitable. Furthermore, the taint analysis reveals a high number of flows with unsanitized paths (10 out of 11), which, despite not being classified as critical or high severity in this analysis, is a strong indicator of potential injection vulnerabilities. This, coupled with a moderate SQL query preparedness rate (only 10% using prepared statements), suggests a significant risk of SQL injection vulnerabilities, even if not explicitly flagged as such in the taint analysis. The plugin's extensive external HTTP requests (28) also introduce potential risks related to server-side request forgery (SSRF) or man-in-the-middle attacks if not handled with utmost care, though no specific issues were flagged in this regard. The absence of past vulnerabilities is a positive sign, but the current static analysis findings, particularly the unprotected entry points and the unsanitized paths in the taint analysis, necessitate caution and further investigation. The plugin appears to have a good intention with regard to output escaping, but the identified weaknesses in authentication and data sanitization are critical oversight.
Key Concerns
- AJAX handlers without auth checks
- High number of unsanitized paths in taint analysis
- Low percentage of prepared SQL statements
- Many external HTTP requests
Manager for Steam Security Vulnerabilities
Manager for Steam Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Manager for Steam Attack Surface
AJAX Handlers 25
Shortcodes 20
WordPress Hooks 20
Scheduled Events 1
Maintenance & Trust
Manager for Steam Maintenance & Trust
Maintenance Signals
Community Trust
Manager for Steam Alternatives
Steam Library GT
steam-library-gt
Display your Steam game library and grab related game information from the thegamesdb.net.
Advanced Steam Widget
advanced-steam-widget
Displays Steam gaming statistics in a widget with increased flexibility, stability, and performance
WPMyAvatar
wpmyavatar
Add a custom avatar (profile picture) from the Wordpress Media Library as user profile picture instead of gravatar.
Default Media Library View
default-media-view
Adds a media library default view selection to the user profile page.
FenShop (gaming shop for minecraft & steam games)
fenshop
Lien vers FenShop - Boutique gaming sur mesure minecraft & steam Link to FenShop - Gaming shop for minecraft & steam games
Manager for Steam Developer Profile
1 plugin · 40 total installs
How We Detect Manager for Steam
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/manager-for-steam/assets/css/steam-manager-profile.css/wp-content/plugins/manager-for-steam/assets/css/steam-manager-library.css/wp-content/plugins/manager-for-steam/assets/css/steam-manager-single-game.css/wp-content/plugins/manager-for-steam/assets/css/steam-manager-wishlist.css/wp-content/plugins/manager-for-steam/assets/css/steam-manager-customizer.css/wp-content/plugins/manager-for-steam/assets/js/steam-manager-preview.js/wp-content/plugins/manager-for-steam/assets/js/steam-manager-game-search.js/wp-content/plugins/manager-for-steam/assets/js/steam-manager-library-filter.js+2 more/wp-content/plugins/manager-for-steam/assets/js/steam-manager-preview.js/wp-content/plugins/manager-for-steam/assets/js/steam-manager-game-search.js/wp-content/plugins/manager-for-steam/assets/js/steam-manager-library-filter.js/wp-content/plugins/manager-for-steam/assets/js/steam-manager-wishlist-filter.js/wp-content/plugins/manager-for-steam/assets/js/steam-manager-customizer.jsmanager-for-steam/assets/css/steam-manager-profile.css?ver=manager-for-steam/assets/css/steam-manager-library.css?ver=manager-for-steam/assets/css/steam-manager-single-game.css?ver=manager-for-steam/assets/css/steam-manager-wishlist.css?ver=manager-for-steam/assets/css/steam-manager-customizer.css?ver=manager-for-steam/assets/js/steam-manager-preview.js?ver=manager-for-steam/assets/js/steam-manager-game-search.js?ver=manager-for-steam/assets/js/steam-manager-library-filter.js?ver=manager-for-steam/assets/js/steam-manager-wishlist-filter.js?ver=manager-for-steam/assets/js/steam-manager-customizer.js?ver=HTML / DOM Fingerprints
steam-manager-profile-wrappersteam-manager-library-gridsteam-manager-game-cardsteam-manager-wishlist-itemsteam-customizer-noticesteam-manager-game-search-results<!-- wp_head --><!-- END wp_head --><!-- TEMPLATE STRUCTURE FOR PROFILE --><!-- END TEMPLATE STRUCTURE FOR PROFILE -->+8 moredata-steam-manager-componentdata-steam-manager-templatedata-steam-manager-steam-iddata-steam-manager-avatar-sizedata-steam-manager-layoutdata-steam-manager-show-status+36 moresteamManagerPreviewsteamManagerGameSearchsteamManagerLibraryFiltersteamManagerWishlistFiltersteamManagerCustomizer/wp-json/steam-manager/v1/game/wp-json/steam-manager/v1/library/wp-json/steam-manager/v1/wishlist[steammanager_profile][steammanager_library][steammanager_game][steammanager_wishlist]