Shortcodes KNVB API Security & Risk Analysis

wordpress.org/plugins/shortcodes-knvb-api

Voetbal clubs in het bezit van een API sleutel voor de KNVB Dataservice kunnen deze plugin gebruiken om API data te tonen in een wordpress website.

10 active installs v1.14.3.10 PHP + WP 3.0.1+ Updated Apr 6, 2017
apidutchknvbsoccervoetbal
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Shortcodes KNVB API Safe to Use in 2026?

Generally Safe

Score 85/100

Shortcodes KNVB API has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The "shortcodes-knvb-api" plugin v1.14.3.10 exhibits a generally positive security posture, primarily due to the absence of known vulnerabilities and the use of prepared statements for all SQL queries. The static analysis indicates a limited attack surface with no identified unprotected entry points, which is a significant strength. However, there are notable areas for improvement that detract from an otherwise robust security profile.

Concerns arise from the incomplete output escaping, with only 56% of outputs being properly sanitized, leaving a substantial portion potentially vulnerable to cross-site scripting (XSS) attacks. Furthermore, the plugin lacks nonce and capability checks across its entry points, which is a critical oversight. While the attack surface is currently small and seemingly unprotected entry points are absent, the lack of these fundamental security mechanisms means that if any new entry points were introduced or existing ones were exploited in unforeseen ways, the plugin would be highly susceptible to unauthorized actions.

The absence of any recorded vulnerabilities in its history is a strong positive indicator. This suggests a commitment to security by the developers, or at least a lack of successful exploitation to date. However, this history, combined with the identified weaknesses in output escaping and the lack of authorization checks, should not be interpreted as a guarantee of future security. The plugin has strengths in its SQL handling and limited attack surface, but the identified vulnerabilities in output escaping and missing authorization controls are significant risks that need to be addressed to achieve a truly secure state.

Key Concerns

  • Insufficient output escaping
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Shortcodes KNVB API Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Shortcodes KNVB API Release Timeline

v1.14.3.10Current
v1.14.3.9
v1.14.3.8
v1.14.3.7
v1.14.3.6
v1.14.3.5
v1.14.3.4
v1.14.3.3
v1.14.3.2
v1.14.3.1
v1.14.3
v1.14.2.2
v1.14.2.1
v1.14.2
v1.14.1
Code Analysis
Analyzed Mar 16, 2026

Shortcodes KNVB API Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
10 escaped
Nonce Checks
0
Capability Checks
0
File Operations
8
External Requests
2
Bundled Libraries
0

Output Escaping

56% escaped18 total outputs
Attack Surface

Shortcodes KNVB API Attack Surface

Entry Points3
Unprotected0

Shortcodes 3

[knvb] shortcode-knvb-api-plugin.php:37
[knvbteam] shortcode-knvb-api-plugin.php:65
[knvbteam-slider] shortcode-knvb-api-plugin.php:89
WordPress Hooks 2
actionadmin_menushortcode-knvb-api-plugin.php:95
actionadmin_initshortcode-knvb-api-plugin.php:96
Maintenance & Trust

Shortcodes KNVB API Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.33
Last updatedApr 6, 2017
PHP min version
Downloads6K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Shortcodes KNVB API Developer Profile

Wimar Schippers

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Shortcodes KNVB API

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/shortcodes-knvb-api/shortcode-knvb-api-style.css

HTML / DOM Fingerprints

CSS Classes
knvbknvbteamteam-resultsteam-rankingteam-scheduleknvbteam-sliderapi-status
HTML Comments
PHP error reporting, should be turned off in production include the KnvbClient class Registreer [knvb ...] Registreer [knvbteam ...]+10 more
Data Attributes
id="api-status-green"id="api-status-red"
Shortcode Output
<div class="knvb"><div class="knvbteam"><div class="team"><div class="team-results">
FAQ

Frequently Asked Questions about Shortcodes KNVB API