
MSTW Schedules & Scoreboards Security & Risk Analysis
wordpress.org/plugins/mstw-schedules-scoreboardsManages multiple sports team schedules and scoreboards. Displays schedule tables, schedule sliders, scoreboards, and countdown timers.
Is MSTW Schedules & Scoreboards Safe to Use in 2026?
Generally Safe
Score 92/100MSTW Schedules & Scoreboards has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The mstw-schedules-scoreboards plugin v1.5.1 exhibits a mixed security posture. On the positive side, there are no recorded vulnerabilities (CVEs), no dangerous functions used, no external HTTP requests, and a reasonable number of nonce and capability checks present on its entry points. The absence of AJAX handlers and REST API routes without authentication checks is also a good sign, significantly reducing the attack surface in those areas.
However, the static analysis reveals several areas of concern. The significant number of file operations (6) coupled with a high percentage of unsanitized paths in taint analysis (3 out of 4 flows) suggests a potential risk of directory traversal or other file-related vulnerabilities. Furthermore, the plugin uses a raw SQL query without prepared statements, which is a common vector for SQL injection attacks. The relatively low percentage of properly escaped output (32%) also raises concerns about cross-site scripting (XSS) vulnerabilities.
While the plugin has no historical CVEs, this doesn't guarantee future security. The identified code signals, particularly the unsanitized paths and unescaped output, represent active risks that should be addressed. The plugin demonstrates good intent with its checks but lacks robust data sanitization and secure SQL practices.
Key Concerns
- Unsanitized paths in taint analysis
- SQL query without prepared statements
- Low percentage of properly escaped output
- Multiple file operations
MSTW Schedules & Scoreboards Security Vulnerabilities
MSTW Schedules & Scoreboards Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
MSTW Schedules & Scoreboards Attack Surface
Shortcodes 5
WordPress Hooks 56
Maintenance & Trust
MSTW Schedules & Scoreboards Maintenance & Trust
Maintenance Signals
Community Trust
MSTW Schedules & Scoreboards Alternatives
CyberPress
cyberpress
Manage eSport Tournaments, Matches, Teams and Players.
Achievements sports league
joomsport-achievements
Sports plugin for motor racing, athletics, aquatics, gymnastics, golf, running, cycling, skiing, poker and similar sports. Manage your league with us!
MSTW League Manager
mstw-league-manager
Manages multiple sports leagues and seasons. Displays schedules and standings in multiple formats.
Matches
matches
This plugin makes it easy to administer and display matches (sports or otherwise) with a neat widget.
MSTW Schedule Builder
mstw-schedule-builder
Builds round-robin games schedules for teams, leagues & tournaments created in the MSTW League Manager plugin.
MSTW Schedules & Scoreboards Developer Profile
7 plugins · 550 total installs
How We Detect MSTW Schedules & Scoreboards
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mstw-schedules-scoreboards/css/mstw-ss-style.css/wp-content/plugins/mstw-schedules-scoreboards/css/mstw-ss-jquery-ui.min.css/wp-content/plugins/mstw-schedules-scoreboards/js/mstw-ss-jquery.min.js/wp-content/plugins/mstw-schedules-scoreboards/js/mstw-ss-jquery-ui.min.js/wp-content/plugins/mstw-schedules-scoreboards/js/mstw-ss-global.js/wp-content/plugins/mstw-schedules-scoreboards/js/mstw-ss-schedule-table.js/wp-content/plugins/mstw-schedules-scoreboards/js/mstw-ss-venue-table.js/wp-content/plugins/mstw-schedules-scoreboards/js/mstw-ss-countdown-timer.js+2 more/wp-content/plugins/mstw-schedules-scoreboards/js/mstw-ss-jquery.min.js/wp-content/plugins/mstw-schedules-scoreboards/js/mstw-ss-jquery-ui.min.js/wp-content/plugins/mstw-schedules-scoreboards/js/mstw-ss-global.js/wp-content/plugins/mstw-schedules-scoreboards/js/mstw-ss-schedule-table.js/wp-content/plugins/mstw-schedules-scoreboards/js/mstw-ss-venue-table.js/wp-content/plugins/mstw-schedules-scoreboards/js/mstw-ss-countdown-timer.js+2 moremstw-schedules-scoreboards/css/mstw-ss-style.css?ver=mstw-schedules-scoreboards/css/mstw-ss-jquery-ui.min.css?ver=mstw-schedules-scoreboards/js/mstw-ss-jquery.min.js?ver=mstw-schedules-scoreboards/js/mstw-ss-jquery-ui.min.js?ver=mstw-schedules-scoreboards/js/mstw-ss-global.js?ver=mstw-schedules-scoreboards/js/mstw-ss-schedule-table.js?ver=mstw-schedules-scoreboards/js/mstw-ss-venue-table.js?ver=mstw-schedules-scoreboards/js/mstw-ss-countdown-timer.js?ver=mstw-schedules-scoreboards/js/mstw-ss-schedule-slider.js?ver=mstw-schedules-scoreboards/js/mstw-ss-scoreboard.js?ver=HTML / DOM Fingerprints
mstw-ss-tablemstw-ss-scoreboard-containermstw-ss-countdown-timer-wrappermstw-ss-schedule-slider-wrapperdata-mstw-ss-game-iddata-mstw-ss-venue-iddata-mstw-ss-team-idmstw_ss_globals[mstw_schedules][mstw_scoreboard][mstw_countdown_timer][mstw_schedule_slider]