Simple WoW Recruitment DE Security & Risk Analysis

wordpress.org/plugins/simple-wow-recruitment-de

Dieses Plugin ermöglicht das einfache Rekrutieren von neuen Spielern für eine World of Warcraft-Gilde.

10 active installs v1.0.8 PHP + WP 3.1+ Updated Oct 2, 2020
guildrecruitmentwarcraftwidgetwow
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Simple WoW Recruitment DE Safe to Use in 2026?

Generally Safe

Score 85/100

Simple WoW Recruitment DE has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The static analysis of 'simple-wow-recruitment-de' v1.0.8 reveals a plugin with a very small attack surface, boasting zero AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, all SQL queries utilize prepared statements, indicating good practice in database interaction. However, a significant concern is the presence of the 'create_function' dangerous function, which can be exploited if user-supplied input is passed to it. Additionally, only 10% of output is properly escaped, leaving the plugin vulnerable to cross-site scripting (XSS) attacks where malicious scripts could be injected and executed in a user's browser. The lack of nonce and capability checks on any entry points, combined with the limited output escaping, are critical weaknesses that could be leveraged by attackers. The vulnerability history being clean is a positive sign, suggesting the developers may have been diligent in the past or the plugin hasn't been a target for known exploits. Despite the lack of known CVEs, the identified code signals and taint analysis (though limited in this report) point to areas requiring immediate attention to prevent potential exploitation.

Key Concerns

  • Use of dangerous function create_function
  • Low output escaping (90% unescaped)
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Simple WoW Recruitment DE Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Simple WoW Recruitment DE Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
0 prepared
Unescaped Output
9
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

create_functionadd_action('widgets_init', create_function('', 'return register_widget("SimpleWowRecruitment");'));simple-wow-recruitment-de.php:149

Output Escaping

10% escaped10 total outputs
Attack Surface

Simple WoW Recruitment DE Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionwidgets_initsimple-wow-recruitment-de.php:149
Maintenance & Trust

Simple WoW Recruitment DE Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedOct 2, 2020
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Simple WoW Recruitment DE Developer Profile

-Danio-

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Simple WoW Recruitment DE

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/simple-wow-recruitment-de/images/class//wp-content/plugins/simple-wow-recruitment-de/images/skills/

HTML / DOM Fingerprints

CSS Classes
daemonenjaegerdruidehexenmeisterjaegerkriegermagiermoenchpaladin+4 more
HTML Comments
This Plugin is a german translation and extension to Pandaria class.Original coding by:Copyright 2010-2011 tumichnix (email: tumichnix at screennetz.de)This program is free software; you can redistribute it and/or modify+7 more
Data Attributes
class="widefat"style="vertical-align: middle"style="margin-top: 10px; list-style-type: none"style="padding-left: 30px"style="margin-left: 10px; width: 150px"style="list-style-type: none"+8 more
FAQ

Frequently Asked Questions about Simple WoW Recruitment DE