
pgn-viewer-for-lichess Security & Risk Analysis
wordpress.org/plugins/pgn-viewer-for-lichessIntegration of lichess-pgn-viewer into WordPress.
Is pgn-viewer-for-lichess Safe to Use in 2026?
Generally Safe
Score 92/100pgn-viewer-for-lichess has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The pgn-viewer-for-lichess plugin version 1.1.1 demonstrates a strong security posture based on the provided static analysis. The absence of dangerous functions, SQL injection vulnerabilities, file operations, external HTTP requests, and proper output escaping are significant strengths. Furthermore, the lack of any recorded vulnerabilities, including CVEs, suggests a history of secure development and maintenance. This plugin appears to implement many best practices for WordPress plugin security.
Despite the overwhelmingly positive static analysis, there are minor areas that could be improved. The absence of nonce checks and capability checks on the single shortcode entry point, while not immediately exploitable due to the lack of critical taint flows or dangerous functions, represents a potential weakness. If the shortcode's functionality were to evolve to handle user-supplied data or perform sensitive actions in the future, these checks would become crucial. However, given the current analysis, the overall risk is low.
In conclusion, the pgn-viewer-for-lichess plugin is currently a very secure option. The developers have evidently prioritized security, resulting in clean code with no apparent critical vulnerabilities. The only minor concern is the potential for future issues if the shortcode's functionality expands without the implementation of authorization and nonce checks.
Key Concerns
- Missing nonce checks on shortcode
- Missing capability checks on shortcode
pgn-viewer-for-lichess Security Vulnerabilities
pgn-viewer-for-lichess Release Timeline
pgn-viewer-for-lichess Code Analysis
Output Escaping
pgn-viewer-for-lichess Attack Surface
Shortcodes 1
WordPress Hooks 2
Maintenance & Trust
pgn-viewer-for-lichess Maintenance & Trust
Maintenance Signals
Community Trust
pgn-viewer-for-lichess Alternatives
RPB Chessboard
rpb-chessboard
This plugin allows you to typeset and display chess diagrams and PGN-encoded chess games.
Embed Chessboard
embed-chessboard
Allows for the insertion of a chessboard displaying chess games within wordpress articles.
Chessgame Shizzle
chessgame-shizzle
Chessgame Shizzle is a nice way to integrate chessgames into your WordPress website. Ideal for chess clubs, your chess blog, or any chess related webs …
PgnViewerJS
pgnviewerjs-wp
Integration of @mliebelt/pgn-viewer into WordPress (formarly named PGNViewerJS).
Chess Game Viewer
chess-game-viewer-control-panel
The Chess Game Viewer Control Panel is the easiest way to add a customizable chess board to your blog.
pgn-viewer-for-lichess Developer Profile
2 plugins · 80 total installs
How We Detect pgn-viewer-for-lichess
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/pgn-viewer-for-lichess/js/lichess-pgn-viewer.js/wp-content/plugins/pgn-viewer-for-lichess/css/lichess-pgn-viewer.css/wp-content/plugins/pgn-viewer-for-lichess/css/lichess-pgn-viewer-custom.css/wp-content/plugins/pgn-viewer-for-lichess/css/editor.css/wp-content/plugins/pgn-viewer-for-lichess/js/index.js/wp-content/plugins/pgn-viewer-for-lichess/js/lichess-pgn-viewer.js/wp-content/plugins/pgn-viewer-for-lichess/js/index.jspgn-viewer-for-lichess/js/lichess-pgn-viewer.js?ver=pgn-viewer-for-lichess/css/lichess-pgn-viewer.css?ver=pgn-viewer-for-lichess/css/lichess-pgn-viewer-custom.css?ver=pgn-viewer-for-lichess/css/editor.css?ver=pgn-viewer-for-lichess/js/index.js?ver=HTML / DOM Fingerprints
lpvlpv-board-lpv-theme-data-pgndata-fendata-showclocksdata-showmovesdata-showcontrolsdata-scrolltomove+5 moreLichessPgnViewer<div id='lpgnv-var viewer = LichessPgnViewer.default || LichessPgnViewer;viewer(document.getElementById('