MTGPulse deckbox embedding tool Security & Risk Analysis

wordpress.org/plugins/mtgpulse-magic-the-gathering-deckbox-plugin

Facilitates embedding of MTGPulse.com deckboxes on your word press site

10 active installs v1.0.3 PHP + WP 2.8.6+ Updated Feb 7, 2012
ccgdeckboxmagic-the-gatheringmtgtcg
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is MTGPulse deckbox embedding tool Safe to Use in 2026?

Generally Safe

Score 85/100

MTGPulse deckbox embedding tool has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 14yr ago
Risk Assessment

The mtgpulse-magic-the-gathering-deckbox-plugin v1.0.3 exhibits a generally good security posture based on the provided static analysis and vulnerability history. The absence of known CVEs and unpatched vulnerabilities is a significant strength, suggesting a commitment to security or a lack of discovered weaknesses.

However, the static analysis reveals a critical concern regarding output escaping. With 100% of observed outputs being unescaped, this plugin is highly susceptible to Cross-Site Scripting (XSS) vulnerabilities. Any data displayed to users that originates from user input or external sources, even if not directly processed by SQL or file operations, could be injected with malicious scripts. While the plugin has capability checks and prepared SQL statements, the lack of output escaping creates a significant attack vector that could be exploited to compromise user sessions or inject malicious content.

The plugin's limited attack surface (2 shortcodes, 0 AJAX, 0 REST API) is a positive aspect, reducing the number of potential entry points. Nevertheless, the unescaped outputs remain the most pressing risk. The plugin's vulnerability history being completely clean is encouraging, but the critical finding in output escaping warrants immediate attention to prevent potential future exploitation.

Key Concerns

  • All outputs unescaped
Vulnerabilities
None known

MTGPulse deckbox embedding tool Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

MTGPulse deckbox embedding tool Release Timeline

No version history available.
Code Analysis
Analyzed Mar 17, 2026

MTGPulse deckbox embedding tool Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
0 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

TinyMCE

Output Escaping

0% escaped3 total outputs
Attack Surface

MTGPulse deckbox embedding tool Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[deckbox] wp_deckbox_mtg.php:77
[deckboxcustom] wp_deckbox_mtg.php:78
WordPress Hooks 5
filtermce_external_pluginswp_deckbox_mtg.php:69
filtermce_buttonswp_deckbox_mtg.php:70
actioninitwp_deckbox_mtg.php:76
actionadmin_menuwp_deckbox_mtg.php:79
actionadmin_initwp_deckbox_mtg.php:80
Maintenance & Trust

MTGPulse deckbox embedding tool Maintenance & Trust

Maintenance Signals

WordPress version tested3.3.2
Last updatedFeb 7, 2012
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

MTGPulse deckbox embedding tool Developer Profile

perstilling

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect MTGPulse deckbox embedding tool

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mtgpulse-deckbox/resources/tinymce3/editor_plugin.js
Script Paths
http://mtgpulse.com/embeddeck.php

HTML / DOM Fingerprints

Shortcode Output
<script type="text/javascript" src="http://mtgpulse.com/embeddeck.php?size=http://mtgpulse.com/embeddeck.php?size=&did=&width=
FAQ

Frequently Asked Questions about MTGPulse deckbox embedding tool