
MCStatusWidget Security & Risk Analysis
wordpress.org/plugins/minecraft-server-status-widgetMCStatusWidget is a widget which show INFO Of Bukkit server.
Is MCStatusWidget Safe to Use in 2026?
Generally Safe
Score 85/100MCStatusWidget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "minecraft-server-status-widget" v1.1 plugin exhibits a mixed security posture. On one hand, it demonstrates good practices by not exposing a large attack surface through AJAX, REST API, shortcodes, or cron events. Furthermore, all identified SQL queries are properly prepared, indicating a mindful approach to database interactions. The absence of known CVEs and historical vulnerabilities is also a positive sign, suggesting a relatively stable codebase concerning previously discovered flaws.
However, several significant concerns emerge from the static analysis. The presence of the `create_function` function is a critical security risk, as it can be exploited to inject and execute arbitrary PHP code. Compounding this, a substantial percentage (100%) of its output is not properly escaped, opening the door to cross-site scripting (XSS) vulnerabilities. The complete lack of nonce and capability checks for its entry points, while the attack surface is zero, is still a concerning oversight. The total absence of taint analysis flows analyzed is also unusual and could mask undiscovered vulnerabilities. In conclusion, while the plugin avoids common pitfalls like unpatched CVEs and extensive attack vectors, the identified `create_function` usage and the pervasive lack of output escaping represent critical security weaknesses that require immediate attention.
Key Concerns
- Use of dangerous create_function
- No output escaping
- No nonce checks
- No capability checks
MCStatusWidget Security Vulnerabilities
MCStatusWidget Code Analysis
Dangerous Functions Found
Output Escaping
MCStatusWidget Attack Surface
WordPress Hooks 1
Maintenance & Trust
MCStatusWidget Maintenance & Trust
Maintenance Signals
Community Trust
MCStatusWidget Alternatives
Server Status For Minecraft PC & PE (MCServerStatus)
server-status-for-minecraft-pc-pe
Server Status For Minecraft PC & PE is a WordPress Widget, show Minecraft Java and Bedrock editions server data.
Minecraft Server Status Checker
minecraft-server-status-checker
This plugin will detect and show the Minecraft Server Status. Works with any kinds of server.
Minestatus
minestatus
Minestatus is a WordPress Widget that enables you to show data from a Minecraft server. It uses the Miners.me REST API to get server data.
Server Status for MC by MrDino
server-status-for-mc-by-mrdino
Display your Minecraft server status on your WordPress site. Basic mode works without any Minecraft plugin.
StatusMC
statusmc
Wyświetla informacje odnośnie serwera bukkit poprzez JSONAPI.//Its shows server status via JsonAPI Plugin.
MCStatusWidget Developer Profile
1 plugin · 10 total installs
How We Detect MCStatusWidget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
MCStatusWidgettoglujStatus: </td><td><b><font style='color:red;'>Offline</font></b>Status: </td><td><b><font style='color:green;'>Online</font></b>IP Port: </td><td><b>Verze: </td><td><b>