
Norse Rune Oracle Plugin Security & Risk Analysis
wordpress.org/plugins/norse-runes-oracleThe Norse Runes Oracle Plugin allows you to interpret single runes or do rune castings.
Is Norse Rune Oracle Plugin Safe to Use in 2026?
Generally Safe
Score 91/100Norse Rune Oracle Plugin has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The plugin 'norse-runes-oracle' v1.4.4 exhibits a generally good security posture based on static analysis, with no identified critical or high severity taint flows and a high percentage of properly escaped output. The plugin demonstrates a commitment to secure coding practices by exclusively using prepared statements for SQL queries and including a nonce check. Furthermore, the absence of external HTTP requests and file operations minimizes common attack vectors. However, the vulnerability history is a significant concern, with two previously disclosed medium severity vulnerabilities, specifically Cross-site Scripting (XSS) and Cross-Site Request Forgery (CSRF). While currently unpatched CVEs are zero, the past occurrence of these vulnerability types suggests potential for future similar weaknesses if not addressed proactively. The presence of 8 shortcodes, although not directly flagged as unprotected, represents a notable attack surface that, combined with past vulnerabilities, warrants careful monitoring.
Key Concerns
- Two medium severity CVEs in vulnerability history
- 8 shortcodes present, increasing attack surface
Norse Rune Oracle Plugin Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Norse Rune Oracle Plugin <= 1.4.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
Norse Rune Oracle Plugin <= 1.4.2 - Cross-Site Request Forgery to Stored Cross-Site Scripting
Norse Rune Oracle Plugin Release Timeline
Norse Rune Oracle Plugin Code Analysis
Output Escaping
Data Flow Analysis
Norse Rune Oracle Plugin Attack Surface
Shortcodes 8
WordPress Hooks 4
Maintenance & Trust
Norse Rune Oracle Plugin Maintenance & Trust
Maintenance Signals
Community Trust
Norse Rune Oracle Plugin Alternatives
Tarot Card Oracle
card-oracle
Create tarot, oracle, cartouche, and rune readings on your WordPress site using your own decks, spreads, and meanings.
Tarot, Oracle cards, Tarot readings, Tarokina
tarokina-free
The best tarot plugin for wordpress. Intuitive and easy to use. Provides accurate tarot readings.
Oracle Cards Lite – Interactive Card Deck Plugin for WordPress
oracle-cards
Interactive Card Deck Plugin for WordPress
EZ Horoscope Professional
ez-horoscope
Astrologically accurate horoscopes with cosmic insights, advice, birth charts, and AI voice agents for chatting about readings.
Divine Astro
horoscope-and-tarot
Divineapi.com is a leading API platform for services like Daily Horoscope, Tarot reading, Kundali, Panchang, Natal Chart, Fortune Cookie, Coffee Cup r …
Norse Rune Oracle Plugin Developer Profile
5 plugins · 740 total installs
How We Detect Norse Rune Oracle Plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.