
Minequery Widget Security & Risk Analysis
wordpress.org/plugins/minequery-widgetDisplay Minecraft server information in your Wordpress with this simple Widget.
Is Minequery Widget Safe to Use in 2026?
Generally Safe
Score 85/100Minequery Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "minequery-widget" v2.0 plugin exhibits a generally positive security posture with some notable exceptions. The absence of known vulnerabilities in its history is a strong indicator of good past development practices. Furthermore, the plugin avoids common attack vectors like AJAX handlers, REST API routes, shortcodes, and cron events that are not properly authenticated, resulting in a zero attack surface in these areas. All SQL queries are also properly prepared, which is excellent. However, the static analysis reveals critical weaknesses. The use of the `create_function` is a significant concern as it's a deprecated and inherently insecure PHP function that can lead to arbitrary code execution if its input is not strictly controlled. The fact that 100% of output is not properly escaped is a major red flag for potential Cross-Site Scripting (XSS) vulnerabilities. The taint analysis showing a flow with unsanitized paths, even if not flagged as critical or high severity in this specific run, combined with the unescaped output, points to a high likelihood of exploitable XSS.
While the lack of known CVEs is reassuring, the presence of `create_function` and widespread unescaped output represents a substantial risk that requires immediate attention. The plugin's strengths lie in its controlled entry points and secure database interactions, but these are overshadowed by the potential for arbitrary code execution and XSS due to insecure coding practices in output handling and function usage. A balanced conclusion is that the plugin is built on a foundation of some good security principles, but critical flaws in `create_function` usage and output sanitization introduce significant vulnerabilities.
Key Concerns
- Use of deprecated/dangerous function create_function
- 100% of outputs are not properly escaped (XSS risk)
- Flow with unsanitized paths found in taint analysis
- No nonce checks implemented
- No capability checks implemented
Minequery Widget Security Vulnerabilities
Minequery Widget Release Timeline
Minequery Widget Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
Minequery Widget Attack Surface
WordPress Hooks 2
Maintenance & Trust
Minequery Widget Maintenance & Trust
Maintenance Signals
Community Trust
Minequery Widget Alternatives
StatusMC
statusmc
Wyświetla informacje odnośnie serwera bukkit poprzez JSONAPI.//Its shows server status via JsonAPI Plugin.
Minestatus
minestatus
Minestatus is a WordPress Widget that enables you to show data from a Minecraft server. It uses the Miners.me REST API to get server data.
MCstatus
mcstatus
MCstatus is a WordPress Widget that enables you to show data from a Minecraft server.
Minecraft Server Status Checker
minecraft-server-status-checker
This plugin will detect and show the Minecraft Server Status. Works with any kinds of server.
MCStatusWidget
minecraft-server-status-widget
MCStatusWidget is a widget which show INFO Of Bukkit server.
Minequery Widget Developer Profile
2 plugins · 70 total installs
How We Detect Minequery Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/minequery-widget/assets/js/minequery.js/wp-content/plugins/minequery-widget/assets/js/minequery.jsminequery-js?ver=HTML / DOM Fingerprints
minequery-widgetminequery-widget-dataminequery-widget-langminequery-widget-urlminequery-widget-resultdata-mq_ipdata-mq_portdata-onlinedata-latencydata-offlinedata-players+1 more<div class="minequery-widget"><div class="minequery-widget-data"<div class="minequery-widget-lang"<div class="minequery-widget-url"