
Runtastic Widget Security & Risk Analysis
wordpress.org/plugins/runtastic-widgetDas ist die erste Version meines Runtastic Widgets. Achtung - das Widget ist aktuell ohne Funktion und eine Weiterentwicklung ist ungewiss.
Is Runtastic Widget Safe to Use in 2026?
Generally Safe
Score 85/100Runtastic Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The runtastic-widget plugin version 1.4 exhibits a generally positive security posture with a very small attack surface and no recorded vulnerabilities. The static analysis shows a complete lack of AJAX handlers, REST API routes, shortcodes, and cron events, indicating minimal potential for external interaction or exploitation. Furthermore, the absence of dangerous functions, file operations, and external HTTP requests is commendable. However, several significant concerns emerge from the code signals. The plugin performs 7 SQL queries, none of which utilize prepared statements, representing a substantial risk of SQL injection vulnerabilities. Additionally, only 17% of output is properly escaped, leaving 83% vulnerable to cross-site scripting (XSS) attacks. The complete absence of nonce and capability checks is also a critical oversight, meaning any functionality, if present, would likely be unprotected against unauthorized access or manipulation.
Key Concerns
- No SQL prepared statements
- Low output escaping percentage
- No nonce checks
- No capability checks
Runtastic Widget Security Vulnerabilities
Runtastic Widget Code Analysis
SQL Query Safety
Output Escaping
Runtastic Widget Attack Surface
WordPress Hooks 1
Maintenance & Trust
Runtastic Widget Maintenance & Trust
Maintenance Signals
Community Trust
Runtastic Widget Developer Profile
1 plugin · 10 total installs
How We Detect Runtastic Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/runtastic-widget/style.css/wp-content/plugins/runtastic-widget/custom-script.jsruntastic-widget/style.css?ver=runtastic-widget/custom-script.js?ver=HTML / DOM Fingerprints
runtastic_widget_classruntastic_widget_id