
Player Transfers for SportsPress Security & Risk Analysis
wordpress.org/plugins/player-transfers-for-sportspressManage and display player transfers seamlessly within SportsPress. Enhance your sports website with structured transfer records and team history.
Is Player Transfers for SportsPress Safe to Use in 2026?
Generally Safe
Score 100/100Player Transfers for SportsPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'player-transfers-for-sportspress' plugin version 1.4.0 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of known CVEs and a clean vulnerability history are positive indicators. The code analysis shows a good adherence to secure coding practices, with all SQL queries utilizing prepared statements and a high percentage of output being properly escaped. Crucially, there are no identified dangerous functions, file operations, external HTTP requests, or taint flows indicating malicious data handling. The plugin also has a limited attack surface, with only one shortcode and no unprotected entry points.
However, there are a few areas that warrant attention. The plugin lacks nonce checks and capability checks, which are fundamental security mechanisms in WordPress for preventing CSRF attacks and ensuring authorized access to functionality. While the current attack surface is small and appears to be protected, the absence of these checks on even a single shortcode introduces a potential risk. The presence of a bundled Freemius library also poses a minor concern, as outdated bundled libraries can sometimes be a vector for vulnerabilities if not kept up-to-date, though the version provided (v1.0) is not inherently alarming without more context on its patch status. Overall, the plugin is well-coded with minimal apparent vulnerabilities, but the omission of nonce and capability checks on its entry points is a notable weakness.
Key Concerns
- Missing nonce checks
- Missing capability checks
- Bundled outdated library (Freemius v1.0)
Player Transfers for SportsPress Security Vulnerabilities
Player Transfers for SportsPress Code Analysis
Bundled Libraries
Output Escaping
Player Transfers for SportsPress Attack Surface
Shortcodes 1
WordPress Hooks 9
Maintenance & Trust
Player Transfers for SportsPress Maintenance & Trust
Maintenance Signals
Community Trust
Player Transfers for SportsPress Alternatives
Soccer Engine – Soccer Plugin for WordPress
soccer-engine-lite
Soccer Engine is a plugin that lets bloggers and clubs add results, fixtures, match commentaries, transfers, and a wide range of stats to articles.
The Soccer Stats
the-soccer-stats
Ultimate tool for your football (soccer) team site.
Football Club Manager
football-club-manager
Easily manage your amateur football club. Create team pages, player info, and integrate match data!
SportsPress for Football (Soccer)
sportspress-for-soccer
SportsPress for Football is an extension for SportsPress, an all-in-one sports data plugin that helps sports clubs set up a football website.
AnWP Football Leagues
football-leagues-by-anwppro
A complete solution for any football site. Knockout and round-robin competitions, player profiles and statistics, squads, standings and stadiums.
Player Transfers for SportsPress Developer Profile
11 plugins · 790 total installs
How We Detect Player Transfers for SportsPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/player-transfers-for-sportspress/assets/css/ptfs-style.css/wp-content/plugins/player-transfers-for-sportspress/assets/js/ptfs-script.jsplayer-transfers-for-sportspress/assets/js/ptfs-script.jsplayer-transfers-for-sportspress/assets/css/ptfs-style.css?ver=player-transfers-for-sportspress/assets/js/ptfs-script.js?ver=HTML / DOM Fingerprints
[player-transfers]