
Shortcodes KNVB API Security & Risk Analysis
wordpress.org/plugins/shortcodes-knvb-apiVoetbal clubs in het bezit van een API sleutel voor de KNVB Dataservice kunnen deze plugin gebruiken om API data te tonen in een wordpress website.
Is Shortcodes KNVB API Safe to Use in 2026?
Generally Safe
Score 85/100Shortcodes KNVB API has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "shortcodes-knvb-api" plugin v1.14.3.10 exhibits a generally positive security posture, primarily due to the absence of known vulnerabilities and the use of prepared statements for all SQL queries. The static analysis indicates a limited attack surface with no identified unprotected entry points, which is a significant strength. However, there are notable areas for improvement that detract from an otherwise robust security profile.
Concerns arise from the incomplete output escaping, with only 56% of outputs being properly sanitized, leaving a substantial portion potentially vulnerable to cross-site scripting (XSS) attacks. Furthermore, the plugin lacks nonce and capability checks across its entry points, which is a critical oversight. While the attack surface is currently small and seemingly unprotected entry points are absent, the lack of these fundamental security mechanisms means that if any new entry points were introduced or existing ones were exploited in unforeseen ways, the plugin would be highly susceptible to unauthorized actions.
The absence of any recorded vulnerabilities in its history is a strong positive indicator. This suggests a commitment to security by the developers, or at least a lack of successful exploitation to date. However, this history, combined with the identified weaknesses in output escaping and the lack of authorization checks, should not be interpreted as a guarantee of future security. The plugin has strengths in its SQL handling and limited attack surface, but the identified vulnerabilities in output escaping and missing authorization controls are significant risks that need to be addressed to achieve a truly secure state.
Key Concerns
- Insufficient output escaping
- Missing nonce checks
- Missing capability checks
Shortcodes KNVB API Security Vulnerabilities
Shortcodes KNVB API Release Timeline
Shortcodes KNVB API Code Analysis
Output Escaping
Shortcodes KNVB API Attack Surface
Shortcodes 3
WordPress Hooks 2
Maintenance & Trust
Shortcodes KNVB API Maintenance & Trust
Maintenance Signals
Community Trust
Shortcodes KNVB API Alternatives
KNVB Api plugin
knvb-api
Show teams:
Football Ranking
football-ranking
Give your users access to updated world rankings for international football (soccer) teams.
Football Club Manager for Sportlink
fcm-for-sportlink
Automatically import Sportlink data into the Football Club Manager WordPress plugin.
Meta for WooCommerce
facebook-for-woocommerce
Get the Official Meta for WooCommerce plugin for powerful ways to help grow your business.
PixelYourSite – Your smart PIXEL (TAG) & API Manager
pixelyoursite
Add Meta Pixel with Conversion API, Google Analytics (GA4) + Consent Mode, Google Tag Manager, and Head & Footer scripts.
Shortcodes KNVB API Developer Profile
1 plugin · 10 total installs
How We Detect Shortcodes KNVB API
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/shortcodes-knvb-api/shortcode-knvb-api-style.cssHTML / DOM Fingerprints
knvbknvbteamteam-resultsteam-rankingteam-scheduleknvbteam-sliderapi-status PHP error reporting, should be turned off in production include the KnvbClient class Registreer [knvb ...] Registreer [knvbteam ...]+10 moreid="api-status-green"id="api-status-red"<div class="knvb"><div class="knvbteam"><div class="team"><div class="team-results">