
Soccer Engine – Soccer Plugin for WordPress Security & Risk Analysis
wordpress.org/plugins/soccer-engine-liteSoccer Engine is a plugin that lets bloggers and clubs add results, fixtures, match commentaries, transfers, and a wide range of stats to articles.
Is Soccer Engine – Soccer Plugin for WordPress Safe to Use in 2026?
Generally Safe
Score 99/100Soccer Engine – Soccer Plugin for WordPress has a strong security track record. Known vulnerabilities have been patched promptly.
The soccer-engine-lite plugin, version 1.14, generally exhibits good security practices, particularly in its handling of SQL queries and output escaping, with high percentages of prepared statements and properly escaped outputs. The absence of critical or high-severity taint analysis findings, alongside a complete lack of unprotected entry points, indicates a solid development approach regarding common web vulnerabilities.
However, the plugin's vulnerability history presents a notable concern. Having a known medium-severity CVE, even if currently patched, suggests that the plugin has had exploitable flaws in the past. The prevalence of Cross-Site Request Forgery (CSRF) as a common vulnerability type is also a point to consider, as these can still be exploited if not mitigated effectively in all user-facing contexts.
Overall, while the code analysis reveals strengths in secure coding practices, the past vulnerability history necessitates ongoing vigilance. The plugin demonstrates good internal security but has shown susceptibility to certain attack vectors, requiring attention to ensure past issues do not resurface or similar vulnerabilities are introduced in future updates. Continued monitoring and prompt patching of any future vulnerabilities are crucial.
Key Concerns
- Medium severity CVE found
Soccer Engine – Soccer Plugin for WordPress Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Soccer Engine – Soccer Plugin for WordPress <= 1.12 - Cross-Site Request Forgery
Soccer Engine – Soccer Plugin for WordPress Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Soccer Engine – Soccer Plugin for WordPress Attack Surface
AJAX Handlers 53
Shortcodes 27
WordPress Hooks 15
Maintenance & Trust
Soccer Engine – Soccer Plugin for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
Soccer Engine – Soccer Plugin for WordPress Alternatives
StatsFC Fixtures
statsfc-fixtures
This widget will display a list of football fixtures on your website, for a chosen competition or team.
StatsFC Next Fixture
statsfc-next-fixture
This widget will show the next fixture for a Premier League team on your website.
SportsPress – Sports Club & League Manager
sportspress
SportsPress is an extendable all-in-one sports data plugin that helps sports clubs set up and manage a league or club site quickly and easily.
JoomSport – for Sports: Team & League, Football, Hockey & more
joomsport-sports-league-results-management
Create PRO sports website for your club, sports team or sports league! Soccer, Football, Hockey, Basketball, Volleyball, Handball, eSport & others.
StatsFC Table
statsfc-table
This widget will place a football league table on your website.
Soccer Engine – Soccer Plugin for WordPress Developer Profile
13 plugins · 30K total installs
How We Detect Soccer Engine – Soccer Plugin for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/soccer-engine-lite/admin/assets/css/general.css/wp-content/plugins/soccer-engine-lite/admin/assets/font/fontello/css/daextsoenl-fontello.css/wp-content/plugins/soccer-engine-lite/public/assets/css/frontend.css/wp-content/plugins/soccer-engine-lite/public/assets/js/frontend.jssoccer-engine-lite/admin/assets/css/general.css?ver=soccer-engine-lite/admin/assets/font/fontello/css/daextsoenl-fontello.css?ver=soccer-engine-lite/public/assets/css/frontend.css?ver=soccer-engine-lite/public/assets/js/frontend.js?ver=HTML / DOM Fingerprints
daextsoenl-fontello<!-- BEGIN: DAEXTSOENL SHORTCODE --><!-- END: DAEXTSOENL SHORTCODE -->data-daextsoenl-shortcode-iddaextsoenl_frontend[daextsoenl_display_matches[daextsoenl_display_competitions[daextsoenl_display_teams[daextsoenl_display_players