My Xbox Profile Security & Risk Analysis

wordpress.org/plugins/my-xbox-profile

Xbox 360 Gamercard Plugin, that displays your Xbox 360 gamertag details anywhere on your website.

10 active installs v2.0 PHP + WP 2.9.0+ Updated May 27, 2010
xboxxbox-gamercardxbox-gamertagxbox-live
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is My Xbox Profile Safe to Use in 2026?

Generally Safe

Score 85/100

My Xbox Profile has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 15yr ago
Risk Assessment

The my-xbox-profile plugin version 2.0 exhibits a mixed security posture. On one hand, it demonstrates good practices by avoiding known dangerous functions, utilizing prepared statements for all SQL queries, and having no recorded vulnerabilities or CVEs. The absence of external HTTP requests and bundled libraries also contributes positively. However, significant concerns arise from the lack of output escaping, which is a critical weakness. With 19 outputs analyzed and 0% properly escaped, this opens the door to Cross-Site Scripting (XSS) vulnerabilities. Furthermore, the taint analysis revealed two flows with unsanitized paths, indicating potential issues with how user-provided data is handled, even if no critical or high severity issues were flagged. The absence of nonce checks and capability checks on its single shortcode entry point is also a notable oversight, potentially allowing unauthorized execution of its functionality. While the plugin has a clean vulnerability history, the identified code analysis issues present real risks that need immediate attention.

Key Concerns

  • Output escaping is completely missing
  • Taint analysis shows unsanitized paths
  • Shortcode lacks nonce check
  • Shortcode lacks capability check
Vulnerabilities
None known

My Xbox Profile Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

My Xbox Profile Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
19
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
3
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped19 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
admin_myxboxprofile (index.php:223)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

My Xbox Profile Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[myxboxprofile] index.php:160
WordPress Hooks 2
actionwp_headindex.php:179
actionadmin_menuindex.php:217
Maintenance & Trust

My Xbox Profile Maintenance & Trust

Maintenance Signals

WordPress version tested2.9.2
Last updatedMay 27, 2010
PHP min version
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

My Xbox Profile Developer Profile

peterjharrison

2 plugins · 40 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect My Xbox Profile

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/my-xbox-profile/css/myxboxprofile.css/wp-content/plugins/my-xbox-profile/js/myxboxprofile_hide.js
Script Paths
http://ajax.googleapis.com/ajax/libs/jquery/1.3.2/jquery.min.js

HTML / DOM Fingerprints

CSS Classes
show_gamedetailsxboxgamercard_gamedetails
HTML Comments
Start Of Code Generated By My Xbox ProfileEnd Of Code Generated By My Xbox Profile
Data Attributes
id="xboxgamercard"id="xboxgamercard_tileurl"id="gamerinfo"id="xboxgamercard_gamertag"id="xboxgamercard_info"id="xboxgamercard_moreinfo"+8 more
JS Globals
jQuery
Shortcode Output
<div id="xboxgamercard"><a href="" target="_blank"><img id="xboxgamercard_tileurl" src="" alt="
FAQ

Frequently Asked Questions about My Xbox Profile