
RiverCraft Security & Risk Analysis
wordpress.org/plugins/rivercraftRiverCraft permet d'unir votre serveur Minecraft et votre site/blog Wordpress à l'aide de JSONAPI.
Is RiverCraft Safe to Use in 2026?
Generally Safe
Score 85/100RiverCraft has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "rivercraft" plugin version 1.3.2 demonstrates a generally positive security posture based on the provided static analysis. The absence of any registered AJAX handlers, REST API routes, shortcodes, or cron events significantly limits its attack surface. Furthermore, the code signals indicate a lack of dangerous functions, no file operations, and the use of prepared statements for all SQL queries, which are excellent security practices. The plugin also refrains from making external HTTP requests, further reducing potential vulnerabilities.
However, the analysis does reveal some areas for concern. A notable weakness is the low percentage of properly escaped output (14%). This indicates a significant risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data or dynamic content may not be adequately neutralized before being displayed to users. Additionally, the absence of nonce checks and capability checks across any identified entry points (though there are none explicitly listed as unprotected) suggests a potential for security bypasses if new entry points were introduced or if the plugin's scope were to expand.
The vulnerability history showing zero known CVEs and no past issues is a strong indicator of good development practices over time. This, combined with the limited attack surface and secure SQL handling, suggests a robust foundation. Nevertheless, the unescaped output remains a critical flaw that requires immediate attention. The overall conclusion is that while "rivercraft" has a strong foundation in terms of attack surface management and data handling, the high prevalence of unescaped output presents a substantial XSS risk that overshadows its other strengths.
Key Concerns
- Low output escaping percentage
- Missing nonce checks
- Missing capability checks
RiverCraft Security Vulnerabilities
RiverCraft Code Analysis
Output Escaping
RiverCraft Attack Surface
WordPress Hooks 2
Maintenance & Trust
RiverCraft Maintenance & Trust
Maintenance Signals
Community Trust
RiverCraft Alternatives
StatusMC
statusmc
Wyświetla informacje odnośnie serwera bukkit poprzez JSONAPI.//Its shows server status via JsonAPI Plugin.
Minecraft Control Panel
minecraft-control-panel
Zeigt Informationen über Deinen Minecraftserver im Front- und Backend an. Mit User- und Gruppenverwaltung, Pluginsteuerung und Serverkontrolle.
Minecraft Server Status Checker
minecraft-server-status-checker
This plugin will detect and show the Minecraft Server Status. Works with any kinds of server.
MCStatusWidget
minecraft-server-status-widget
MCStatusWidget is a widget which show INFO Of Bukkit server.
MC Server Status
mc-server-status
Displays the Minecraft server status along with the active players.
RiverCraft Developer Profile
1 plugin · 10 total installs
How We Detect RiverCraft
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/rivercraft/css/style.cssrivercraft/css/style.css?ver=