SportsPress for Baseball Security & Risk Analysis

wordpress.org/plugins/sportspress-for-baseball

SportsPress for Baseball is an extension for SportsPress, an all-in-one sports data plugin that helps sports teams set up a baseball website.

1K active installs v1.0.2 PHP + WP 3.8+ Updated Aug 27, 2020
playerssportsportsstatisticsstats
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is SportsPress for Baseball Safe to Use in 2026?

Generally Safe

Score 85/100

SportsPress for Baseball has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The plugin "sportspress-for-baseball" v1.0.2 exhibits a strong security posture based on the provided static analysis. The absence of identified AJAX handlers, REST API routes, shortcodes, and cron events suggests a minimal attack surface, with zero reported entry points lacking authentication. Furthermore, the code analysis reveals no dangerous functions, no raw SQL queries (all use prepared statements), and a high percentage of properly escaped output. The presence of nonce and capability checks indicates adherence to WordPress security best practices for handling user actions and permissions. The lack of file operations and external HTTP requests also reduces potential security risks.

The vulnerability history is clean, with no recorded CVEs, making it difficult to identify any historical patterns of weakness. The taint analysis also yielded no critical or high severity flows, reinforcing the current assessment of low risk. Overall, this plugin appears to be well-developed from a security perspective, with a limited attack surface and good implementation of core WordPress security features. The primary strength lies in the proactive avoidance of common vulnerabilities through careful coding practices. The only potential minor concern, which is not significant enough to warrant a deduction given the overall context, would be the small percentage of outputs that are not properly escaped (9%), though this is a very low number.

Vulnerabilities
None known

SportsPress for Baseball Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

SportsPress for Baseball Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
82 escaped
Nonce Checks
5
Capability Checks
13
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

91% escaped90 total outputs
Attack Surface

SportsPress for Baseball Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 40
actioninitincludes\class-tgm-plugin-activation.php:268
filterload_textdomain_mofileincludes\class-tgm-plugin-activation.php:269
actioninitincludes\class-tgm-plugin-activation.php:272
actionadmin_menuincludes\class-tgm-plugin-activation.php:421
actionadmin_headincludes\class-tgm-plugin-activation.php:422
filterinstall_plugin_complete_actionsincludes\class-tgm-plugin-activation.php:425
filterupdate_plugin_complete_actionsincludes\class-tgm-plugin-activation.php:426
actionadmin_noticesincludes\class-tgm-plugin-activation.php:429
actionadmin_initincludes\class-tgm-plugin-activation.php:430
actionadmin_enqueue_scriptsincludes\class-tgm-plugin-activation.php:431
actionload-plugins.phpincludes\class-tgm-plugin-activation.php:436
actionswitch_themeincludes\class-tgm-plugin-activation.php:439
actionswitch_themeincludes\class-tgm-plugin-activation.php:442
actionadmin_initincludes\class-tgm-plugin-activation.php:447
actionswitch_themeincludes\class-tgm-plugin-activation.php:452
actionload_textdomain_mofileincludes\class-tgm-plugin-activation.php:475
filterupgrader_source_selectionincludes\class-tgm-plugin-activation.php:889
actionplugins_loadedincludes\class-tgm-plugin-activation.php:2112
filtertgmpa_table_data_itemsincludes\class-tgm-plugin-activation.php:2236
filterupgrader_source_selectionincludes\class-tgm-plugin-activation.php:2977
actionadmin_initincludes\class-tgm-plugin-activation.php:3147
actionupgrader_process_completeincludes\class-tgm-plugin-activation.php:3242
filterupgrader_post_installincludes\class-tgm-plugin-activation.php:3301
filterupgrader_post_installincludes\class-tgm-plugin-activation.php:3446
actionadmin_enqueue_scriptssportspress-for-baseball.php:39
actiontgmpa_registersportspress-for-baseball.php:40
filtergettextsportspress-for-baseball.php:42
filtersportspress_event_empty_result_stringsportspress-for-baseball.php:43
filtersportspress_event_performance_default_squad_numbersportspress-for-baseball.php:44
filtersportspress_event_performance_show_numberssportspress-for-baseball.php:45
filtersportspress_default_sportsportspress-for-baseball.php:48
actionsportspress_meta_box_performance_detailssportspress-for-baseball.php:51
actionsportspress_process_sp_performance_metasportspress-for-baseball.php:52
actionsportspress_before_event_performancesportspress-for-baseball.php:53
filtersportspress_event_performance_add_valuesportspress-for-baseball.php:54
filtersportspress_event_performance_table_total_valuesportspress-for-baseball.php:55
actionsportspress_before_player_statistics_loopsportspress-for-baseball.php:56
filtersportspress_player_performance_add_valuesportspress-for-baseball.php:57
filtersportspress_player_performance_table_placeholdersportspress-for-baseball.php:58
filtersportspress_player_performance_table_placeholderssportspress-for-baseball.php:59
Maintenance & Trust

SportsPress for Baseball Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedAug 27, 2020
PHP min version
Downloads16K

Community Trust

Rating90/100
Number of ratings2
Active installs1K
Developer Profile

SportsPress for Baseball Developer Profile

ThemeBoy

12 plugins · 21K total installs

68
trust score
Avg Security Score
84/100
Avg Patch Time
360 days
View full developer profile
Detection Fingerprints

How We Detect SportsPress for Baseball

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sportspress-for-baseball/css/admin.css

HTML / DOM Fingerprints

CSS Classes
sp-desc-tip
FAQ

Frequently Asked Questions about SportsPress for Baseball