Meeple Like Us Boardgamegeek Plugin Security & Risk Analysis

wordpress.org/plugins/meeple-like-us-boardgamegeek

Note: This plugin makes use of an external API that is to be found at http://imaginary-realities.com/bggapi/. This is a service hosted via JustHost i …

70 active installs v1.6.5 PHP 5.2.4+ WP 3.0.1+ Updated Mar 10, 2021
accessibilityboardgameboardgamegeekgaming
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Meeple Like Us Boardgamegeek Plugin Safe to Use in 2026?

Generally Safe

Score 85/100

Meeple Like Us Boardgamegeek Plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The plugin 'meeple-like-us-boardgamegeek' v1.6.5 exhibits a generally strong security posture based on the provided static analysis. The absence of critical or high severity taint flows, along with 100% properly escaped output, is a significant strength. Furthermore, the plugin has no recorded vulnerabilities or CVEs, indicating a history of stable and secure development. The use of prepared statements for a majority of SQL queries also suggests a good practice in database interaction.

However, the analysis does highlight some areas for improvement. The complete absence of nonce checks across all entry points, including the 22 shortcodes, represents a potential risk. While there are no unauthenticated AJAX or REST API endpoints, shortcodes can be invoked in various contexts where nonce validation is crucial to prevent Cross-Site Request Forgery (CSRF) attacks. The presence of file operations without explicit context in the analysis also warrants a degree of caution, as their implementation could introduce vulnerabilities if not handled securely.

In conclusion, the plugin is largely secure with a clean vulnerability history and good output sanitization. The primary concern lies in the lack of nonce checks on its entry points, particularly shortcodes, which could expose it to CSRF attacks under specific circumstances. Addressing this would further solidify its security.

Key Concerns

  • Missing nonce checks on entry points
Vulnerabilities
None known

Meeple Like Us Boardgamegeek Plugin Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Meeple Like Us Boardgamegeek Plugin Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
2 prepared
Unescaped Output
0
74 escaped
Nonce Checks
0
Capability Checks
0
File Operations
2
External Requests
0
Bundled Libraries
0

SQL Query Safety

67% prepared3 total queries

Output Escaping

100% escaped74 total outputs
Attack Surface

Meeple Like Us Boardgamegeek Plugin Attack Surface

Entry Points22
Unprotected0

Shortcodes 22

[bgg] bgg.php:1997
[mlu_label] bgg.php:1998
[bgg_rating] bgg.php:1999
[bgg_complexity] bgg.php:2000
[bgg_image] bgg.php:2001
[bgg_rank] bgg.php:2002
[bgg_weight] bgg.php:2003
[bgg_description] bgg.php:2004
[mlu_table] bgg.php:2005
[mlu_radar] bgg.php:2006
[mlu_bar] bgg.php:2007
[mlu_toc] bgg.php:2008
[mlu_master] bgg.php:2009
[bgg_collection] bgg.php:2010
[mlu_scotlight] bgg.php:2011
[mlu_stats_coverage] bgg.php:2012
[mlu_stats_publisher] bgg.php:2013
[mlu_stats_all_publishers] bgg.php:2014
[mlu_rating] bgg.php:2015
[mlu_recommendations] bgg.php:2016
[mlu_game_idea] bgg.php:2017
[hob_coc] bgg.php:2018
WordPress Hooks 2
actionadmin_menubgg_options.php:9
actionadmin_initbgg_options.php:45
Maintenance & Trust

Meeple Like Us Boardgamegeek Plugin Maintenance & Trust

Maintenance Signals

WordPress version tested5.7.15
Last updatedMar 10, 2021
PHP min version5.2.4
Downloads2K

Community Trust

Rating60/100
Number of ratings2
Active installs70
Developer Profile

Meeple Like Us Boardgamegeek Plugin Developer Profile

drakkos

1 plugin · 70 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Meeple Like Us Boardgamegeek Plugin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/meeple-like-us-boardgamegeek/meeple.css
Version Parameters
meeple-like-us-boardgamegeek/meeple.css?ver=

HTML / DOM Fingerprints

CSS Classes
meeple_like_us_rowmeeple_like_us_valuemeeple_like_us_keymeeple_like_us_containermeeple_like_us_tablemeeple_like_us_table_header
Data Attributes
data-mlubgg-id
Shortcode Output
<div class = "meeple_like_us_container"><table cellpadding = "0" class = "meeple_like_us_table"><th style = "text-align: center;" colspan = "2"><a href = "http://meeplelikeus.co.uk/meeple-like-us-plugin/"
FAQ

Frequently Asked Questions about Meeple Like Us Boardgamegeek Plugin