Sel Church Sermon Security & Risk Analysis

wordpress.org/plugins/sel-church-sermons

This plugin created for official church themes from Selthemes.com

10 active installs v1.0.1 PHP + WP 4.0+ Updated Aug 11, 2017
churchchurch-sermonsermons
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Sel Church Sermon Safe to Use in 2026?

Generally Safe

Score 85/100

Sel Church Sermon has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The "sel-church-sermons" v1.0.1 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points significantly limits its attack surface. The code signals further reinforce this, with no dangerous functions, all SQL queries using prepared statements, and the presence of nonce and capability checks. File operations and external HTTP requests are also absent, further reducing potential vulnerabilities.

The plugin demonstrates good practices regarding output escaping, with a high percentage (78%) of outputs properly escaped, although a small percentage remains unescaped. Taint analysis reveals no identified flows with unsanitized paths, indicating no critical or high-severity security risks in this area. The vulnerability history is also a strong positive, with zero known CVEs, indicating a lack of historical security weaknesses.

While the plugin has a very limited attack surface and appears to have been developed with security in mind, the fact that 22% of outputs are not properly escaped represents a minor concern. This could potentially lead to cross-site scripting (XSS) vulnerabilities if sensitive data is displayed without sufficient sanitization in those specific instances. However, given the overall lack of exploitable entry points and historical vulnerabilities, this plugin appears to be relatively secure.

Key Concerns

  • Improperly escaped output present
Vulnerabilities
None known

Sel Church Sermon Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Sel Church Sermon Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
24
85 escaped
Nonce Checks
5
Capability Checks
13
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

78% escaped109 total outputs
Attack Surface

Sel Church Sermon Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 34
filtermanage_selthemes_sermon_posts_columnsinc\sermons-columns.php:17
actionmanage_selthemes_sermon_posts_custom_columninc\sermons-columns.php:18
actioncmb2_admin_initinc\sermons-meta.php:16
actioninitinc\sermons-post-type.php:82
actioninitinc\sermons-post-type.php:134
actioninitinc\sermons-post-type.php:186
actioninitinc\sermons-post-type.php:237
actioninitinc\sermons-post-type.php:287
actioninitinc\tgmpa\class-tgm-plugin-activation.php:268
filterload_textdomain_mofileinc\tgmpa\class-tgm-plugin-activation.php:269
actioninitinc\tgmpa\class-tgm-plugin-activation.php:272
actionadmin_menuinc\tgmpa\class-tgm-plugin-activation.php:421
actionadmin_headinc\tgmpa\class-tgm-plugin-activation.php:422
filterinstall_plugin_complete_actionsinc\tgmpa\class-tgm-plugin-activation.php:425
filterupdate_plugin_complete_actionsinc\tgmpa\class-tgm-plugin-activation.php:426
actionadmin_noticesinc\tgmpa\class-tgm-plugin-activation.php:429
actionadmin_initinc\tgmpa\class-tgm-plugin-activation.php:430
actionadmin_enqueue_scriptsinc\tgmpa\class-tgm-plugin-activation.php:431
actionload-plugins.phpinc\tgmpa\class-tgm-plugin-activation.php:436
actionswitch_themeinc\tgmpa\class-tgm-plugin-activation.php:439
actionswitch_themeinc\tgmpa\class-tgm-plugin-activation.php:442
actionadmin_initinc\tgmpa\class-tgm-plugin-activation.php:447
actionswitch_themeinc\tgmpa\class-tgm-plugin-activation.php:452
actionload_textdomain_mofileinc\tgmpa\class-tgm-plugin-activation.php:475
filterupgrader_source_selectioninc\tgmpa\class-tgm-plugin-activation.php:889
actionplugins_loadedinc\tgmpa\class-tgm-plugin-activation.php:2112
filtertgmpa_table_data_itemsinc\tgmpa\class-tgm-plugin-activation.php:2236
filterupgrader_source_selectioninc\tgmpa\class-tgm-plugin-activation.php:2977
actionadmin_initinc\tgmpa\class-tgm-plugin-activation.php:3147
actionupgrader_process_completeinc\tgmpa\class-tgm-plugin-activation.php:3242
filterupgrader_post_installinc\tgmpa\class-tgm-plugin-activation.php:3301
filterupgrader_post_installinc\tgmpa\class-tgm-plugin-activation.php:3446
actiontgmpa_registerinc\tgmpa\required-plugin.php:36
actionwidgets_initplugin.php:61
Maintenance & Trust

Sel Church Sermon Maintenance & Trust

Maintenance Signals

WordPress version tested4.8.28
Last updatedAug 11, 2017
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Sel Church Sermon Developer Profile

Selthemes

4 plugins · 40 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Sel Church Sermon

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sel-church-sermons/inc/css/tgm-plugin-activation.css/wp-content/plugins/sel-church-sermons/inc/js/tgm-plugin-activation.js/wp-content/plugins/sel-church-sermons/inc/css/sermons-admin.css
Script Paths
/wp-content/plugins/sel-church-sermons/inc/js/tgm-plugin-activation.js
Version Parameters
sel-church-sermons/inc/css/tgm-plugin-activation.css?ver=sel-church-sermons/inc/js/tgm-plugin-activation.js?ver=sel-church-sermons/inc/css/sermons-admin.css?ver=

HTML / DOM Fingerprints

CSS Classes
tgmpa-noticetgmpa-plugin-name
Data Attributes
data-slug
JS Globals
tgmpa
FAQ

Frequently Asked Questions about Sel Church Sermon