Minestatus Security & Risk Analysis

wordpress.org/plugins/minestatus

Minestatus is a WordPress Widget that enables you to show data from a Minecraft server. It uses the Miners.me REST API to get server data.

30 active installs v3.0.1 PHP + WP 3.0+ Updated Sep 21, 2016
minecraftminequeryserverstatus
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Minestatus Safe to Use in 2026?

Generally Safe

Score 85/100

Minestatus has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the 'minestatus' plugin version 3.0.1 exhibits a strong security posture. The static analysis reveals no exploitable attack surface through common entry points like AJAX, REST API, shortcodes, or cron events. Furthermore, the code demonstrates excellent security practices, with no dangerous functions identified, all SQL queries utilizing prepared statements, and all output being properly escaped. The absence of file operations, external HTTP requests, and apparent lack of security checks like nonce or capability checks on its zero entry points is noteworthy, suggesting a simple or inactive functionality that doesn't require these measures within its current scope. The taint analysis further reinforces this, showing no unsanitized data flows, indicating a low risk of injection vulnerabilities.

The plugin's vulnerability history is equally impressive, with a complete absence of any recorded CVEs. This indicates a history of responsible development and diligent patching, or more likely, a plugin that has not historically presented exploitable security flaws. The lack of common vulnerability types and recent vulnerabilities further solidifies its clean record.

In conclusion, 'minestatus' v3.0.1 appears to be a highly secure plugin. Its strengths lie in its minimal attack surface, robust coding practices regarding SQL and output sanitization, and a spotless vulnerability history. The only area of potential concern, though not explicitly a vulnerability in this analysis, is the complete absence of nonce and capability checks. While this is acceptable given the current lack of entry points and taint flows, any future expansion or introduction of new features without these checks could introduce significant risks. For now, the plugin is considered very low risk.

Vulnerabilities
None known

Minestatus Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Minestatus Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Minestatus Attack Surface

Entry Points0
Unprotected0
Maintenance & Trust

Minestatus Maintenance & Trust

Maintenance Signals

WordPress version tested4.6.30
Last updatedSep 21, 2016
PHP min version
Downloads30K

Community Trust

Rating60/100
Number of ratings8
Active installs30
Developer Profile

Minestatus Developer Profile

Jeroen Weustink

1 plugin · 30 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Minestatus

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/minestatus/css/minestatus-style.css/wp-content/plugins/minestatus/js/minestatus-script.js
Script Paths
/wp-content/plugins/minestatus/js/minestatus-script.js
Version Parameters
minestatus-style.css?ver=minestatus-script.js?ver=

HTML / DOM Fingerprints

CSS Classes
minestatus-widget-titleminestatus-widget-contentminestatus-server-statusminestatus-player-countminestatus-motdminestatus-version
Data Attributes
data-addressdata-portdata-querydata-protocol
JS Globals
minestatus_ajax_object
Shortcode Output
[minestatus[/minestatus]
FAQ

Frequently Asked Questions about Minestatus