
MTGPulse deckbox embedding tool Security & Risk Analysis
wordpress.org/plugins/mtgpulse-magic-the-gathering-deckbox-pluginFacilitates embedding of MTGPulse.com deckboxes on your word press site
Is MTGPulse deckbox embedding tool Safe to Use in 2026?
Generally Safe
Score 85/100MTGPulse deckbox embedding tool has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The mtgpulse-magic-the-gathering-deckbox-plugin v1.0.3 exhibits a generally good security posture based on the provided static analysis and vulnerability history. The absence of known CVEs and unpatched vulnerabilities is a significant strength, suggesting a commitment to security or a lack of discovered weaknesses.
However, the static analysis reveals a critical concern regarding output escaping. With 100% of observed outputs being unescaped, this plugin is highly susceptible to Cross-Site Scripting (XSS) vulnerabilities. Any data displayed to users that originates from user input or external sources, even if not directly processed by SQL or file operations, could be injected with malicious scripts. While the plugin has capability checks and prepared SQL statements, the lack of output escaping creates a significant attack vector that could be exploited to compromise user sessions or inject malicious content.
The plugin's limited attack surface (2 shortcodes, 0 AJAX, 0 REST API) is a positive aspect, reducing the number of potential entry points. Nevertheless, the unescaped outputs remain the most pressing risk. The plugin's vulnerability history being completely clean is encouraging, but the critical finding in output escaping warrants immediate attention to prevent potential future exploitation.
Key Concerns
- All outputs unescaped
MTGPulse deckbox embedding tool Security Vulnerabilities
MTGPulse deckbox embedding tool Release Timeline
MTGPulse deckbox embedding tool Code Analysis
Bundled Libraries
Output Escaping
MTGPulse deckbox embedding tool Attack Surface
Shortcodes 2
WordPress Hooks 5
Maintenance & Trust
MTGPulse deckbox embedding tool Maintenance & Trust
Maintenance Signals
Community Trust
MTGPulse deckbox embedding tool Alternatives
Magic the Gathering Card Tooltips
magic-the-gathering-card-tooltips
Easily transform Magic the Gathering card names into links that show the card image in a tooltip when hovering over them. You can also quickly create …
MtG-Tutor.de CardLinker
mtg-tutorde-cardlinker
This plugin provides some shortcode to easily link MtG Cards and Decks! - Ein Plugin mit dem man ganz leicht MtG Karten und Decks verlinken kann!
CCG Manager
ccg-manager
A WordPress plugin to manage your CCG collection
TCG Card Links
tcg-card-links
The goal of this Plug-in is to provide an instantaneous way for you to turn all Magic: the Gathering card names within your blog posts into card infor …
WP MtG-Helper
wp-mtg-helper
The goal of this plugin is to help you writing articels about Magic: the Gathering like tournament reports or draft walkthroughs and reducing the time …
MTGPulse deckbox embedding tool Developer Profile
1 plugin · 10 total installs
How We Detect MTGPulse deckbox embedding tool
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mtgpulse-deckbox/resources/tinymce3/editor_plugin.jshttp://mtgpulse.com/embeddeck.phpHTML / DOM Fingerprints
<script type="text/javascript" src="http://mtgpulse.com/embeddeck.php?size=http://mtgpulse.com/embeddeck.php?size=&did=&width=