
MSTW League Manager Security & Risk Analysis
wordpress.org/plugins/mstw-league-managerManages multiple sports leagues and seasons. Displays schedules and standings in multiple formats.
Is MSTW League Manager Safe to Use in 2026?
High Risk
Score 48/100MSTW League Manager carries significant security risk with 2 known CVEs, 2 still unpatched. Consider switching to a maintained alternative.
The "mstw-league-manager" v2.10 plugin exhibits a concerning security posture, primarily due to a significant number of unprotected AJAX handlers and a lack of proper input sanitization for file operations. While the plugin avoids dangerous functions and external HTTP requests, the presence of raw SQL queries and a low percentage of properly escaped output outputs indicate potential vulnerabilities that could be exploited. The historical vulnerability data, which includes a medium-severity CVE, suggests a recurring pattern of security weaknesses. Despite some good practices like the use of capability checks and nonces in a limited capacity, the overall risk is elevated by the unprotected entry points and the critical findings in the taint analysis.
Key Concerns
- Unprotected AJAX handlers
- SQL queries not using prepared statements
- Low percentage of properly escaped output
- Flows with unsanitized paths
- Unpatched CVE (medium severity)
MSTW League Manager Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
MSTW League Manager <= 2.10 - Authenticated (Contributor+) Stored Cross-Site Scripting
MSTW League Manager <= 2.10 - Cross-Site Request Forgery
MSTW League Manager Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
MSTW League Manager Attack Surface
AJAX Handlers 7
Shortcodes 13
WordPress Hooks 71
Maintenance & Trust
MSTW League Manager Maintenance & Trust
Maintenance Signals
Community Trust
MSTW League Manager Alternatives
MSTW Schedule Builder
mstw-schedule-builder
Builds round-robin games schedules for teams, leagues & tournaments created in the MSTW League Manager plugin.
WP Club Manager – WordPress Sports Club Plugin
wp-club-manager
WP Club Manager is easy to set-up and has everything you need to build and manage an amazing sports club website.
CyberPress
cyberpress
Manage eSport Tournaments, Matches, Teams and Players.
Team Rosters
team-rosters
Manages multiple team rosters. Creates roster tables, player galleries, and player profile pages.
Sportsteam Widget – Football livescore
sportsteam-widget
A widget that shows the next match of a team.
MSTW League Manager Developer Profile
7 plugins · 550 total installs
How We Detect MSTW League Manager
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mstw-league-manager/css/mstw-lm-admin.css/wp-content/plugins/mstw-league-manager/css/mstw-lm-styles.css/wp-content/plugins/mstw-league-manager/css/mstw-lm-team-schedule-styles.css/wp-content/plugins/mstw-league-manager/css/mstw-lm-league-schedule-styles.css/wp-content/plugins/mstw-league-manager/css/mstw-lm-schedule-gallery-styles.css/wp-content/plugins/mstw-league-manager/css/mstw-lm-admin-schedule-edit-styles.css/wp-content/plugins/mstw-league-manager/js/mstw-lm-admin.js/wp-content/plugins/mstw-league-manager/js/mstw-lm-teams.js+3 more/wp-content/plugins/mstw-league-manager/js/mstw-lm-admin.js/wp-content/plugins/mstw-league-manager/js/mstw-lm-teams.js/wp-content/plugins/mstw-league-manager/js/mstw-lm-leagues.js/wp-content/plugins/mstw-league-manager/js/mstw-lm-schedule-edit.js/wp-content/plugins/mstw-league-manager/js/mstw-lm-schedule-gallery.jsmstw-league-manager/css/mstw-lm-admin.css?ver=mstw-league-manager/css/mstw-lm-styles.css?ver=mstw-league-manager/css/mstw-lm-team-schedule-styles.css?ver=mstw-league-manager/css/mstw-lm-league-schedule-styles.css?ver=mstw-league-manager/css/mstw-lm-schedule-gallery-styles.css?ver=mstw-league-manager/css/mstw-lm-admin-schedule-edit-styles.css?ver=mstw-league-manager/js/mstw-lm-admin.js?ver=mstw-league-manager/js/mstw-lm-teams.js?ver=mstw-league-manager/js/mstw-lm-leagues.js?ver=mstw-league-manager/js/mstw-lm-schedule-edit.js?ver=mstw-league-manager/js/mstw-lm-schedule-gallery.js?ver=HTML / DOM Fingerprints
mstw-lm-admin-noticemstw-lm-team-datamstw-lm-league-datamstw-lm-schedule-tablemstw-lm-league-schedulemstw-lm-schedule-gallerymstw-lm-schedule-edit-form<!-- MSTW League Manager: Begin Team Edit Form --><!-- MSTW League Manager: Begin League Edit Form --><!-- MSTW League Manager: Begin Schedule Edit Form --><!-- MSTW League Manager: End Schedule Edit Form -->+4 moredata-mstw-lm-team-iddata-mstw-lm-league-iddata-mstw-lm-schedule-idmstw_lm_admin_optionsmstw_lm_teams_optionsmstw_lm_leagues_optionsmstw_lm_schedule_edit_optionsmstw_lm_schedule_gallery_options/wp-json/mstw-league-manager/v1/teams/wp-json/mstw-league-manager/v1/leagues/wp-json/mstw-league-manager/v1/schedules[mstw_lm_team][mstw_lm_league][mstw_lm_schedule_table][mstw_lm_multi_schedule_table]