SportsPress for Basketball Security & Risk Analysis

wordpress.org/plugins/sportspress-for-basketball

SportsPress for Basketball is an extension for SportsPress, an all-in-one sports data plugin that helps sports teams set up a basketball website.

1K active installs v0.9.1 PHP + WP 3.8+ Updated Aug 27, 2020
basketballbasketball-teamplayerssportsports
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is SportsPress for Basketball Safe to Use in 2026?

Generally Safe

Score 85/100

SportsPress for Basketball has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The plugin "sportspress-for-basketball" v0.9.1 exhibits a generally strong security posture based on the provided static analysis. The absence of any reported CVEs, both historically and currently unpatched, is a significant positive indicator. The code analysis reveals no dangerous functions, no file operations, and no external HTTP requests, all of which are good security practices. Furthermore, the complete absence of raw SQL queries, with 100% using prepared statements, and a high percentage of properly escaped output (91%) demonstrate a commitment to preventing common web vulnerabilities like SQL injection and XSS. The presence of nonce and capability checks, although their specific implementation is not detailed, also suggests an awareness of access control mechanisms. The attack surface is reported as zero, meaning no AJAX handlers, REST API routes, shortcodes, or cron events were detected, which significantly reduces the potential for exploitation through these common entry points. However, the static analysis also indicates zero taint flows analyzed, which means the absence of critical or high severity taint issues is not a confirmed finding but rather an absence of analysis. While the plugin appears well-secured based on current data, the lack of taint analysis prevents a complete assurance against certain types of sophisticated vulnerabilities that might not be caught by the other static checks.

Key Concerns

  • No taint flows analyzed
Vulnerabilities
None known

SportsPress for Basketball Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

SportsPress for Basketball Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
81 escaped
Nonce Checks
5
Capability Checks
13
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

91% escaped89 total outputs
Attack Surface

SportsPress for Basketball Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 29
actioninitincludes\class-tgm-plugin-activation.php:268
filterload_textdomain_mofileincludes\class-tgm-plugin-activation.php:269
actioninitincludes\class-tgm-plugin-activation.php:272
actionadmin_menuincludes\class-tgm-plugin-activation.php:421
actionadmin_headincludes\class-tgm-plugin-activation.php:422
filterinstall_plugin_complete_actionsincludes\class-tgm-plugin-activation.php:425
filterupdate_plugin_complete_actionsincludes\class-tgm-plugin-activation.php:426
actionadmin_noticesincludes\class-tgm-plugin-activation.php:429
actionadmin_initincludes\class-tgm-plugin-activation.php:430
actionadmin_enqueue_scriptsincludes\class-tgm-plugin-activation.php:431
actionload-plugins.phpincludes\class-tgm-plugin-activation.php:436
actionswitch_themeincludes\class-tgm-plugin-activation.php:439
actionswitch_themeincludes\class-tgm-plugin-activation.php:442
actionadmin_initincludes\class-tgm-plugin-activation.php:447
actionswitch_themeincludes\class-tgm-plugin-activation.php:452
actionload_textdomain_mofileincludes\class-tgm-plugin-activation.php:475
filterupgrader_source_selectionincludes\class-tgm-plugin-activation.php:889
actionplugins_loadedincludes\class-tgm-plugin-activation.php:2112
filtertgmpa_table_data_itemsincludes\class-tgm-plugin-activation.php:2236
filterupgrader_source_selectionincludes\class-tgm-plugin-activation.php:2977
actionadmin_initincludes\class-tgm-plugin-activation.php:3147
actionupgrader_process_completeincludes\class-tgm-plugin-activation.php:3242
filterupgrader_post_installincludes\class-tgm-plugin-activation.php:3301
filterupgrader_post_installincludes\class-tgm-plugin-activation.php:3446
actioninitsportspress-for-basketball.php:34
actionadmin_enqueue_scriptssportspress-for-basketball.php:36
actiontgmpa_registersportspress-for-basketball.php:37
filtergettextsportspress-for-basketball.php:39
filtersportspress_default_sportsportspress-for-basketball.php:42
Maintenance & Trust

SportsPress for Basketball Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedAug 27, 2020
PHP min version
Downloads40K

Community Trust

Rating0/100
Number of ratings0
Active installs1K
Developer Profile

SportsPress for Basketball Developer Profile

ThemeBoy

12 plugins · 21K total installs

68
trust score
Avg Security Score
84/100
Avg Patch Time
360 days
View full developer profile
Detection Fingerprints

How We Detect SportsPress for Basketball

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sportspress-for-basketball/css/admin.css/wp-content/plugins/sportspress-for-basketball/js/admin.js
Script Paths
/wp-content/plugins/sportspress-for-basketball/js/admin.js
Version Parameters
sportspress-basketball-adminsportspress-basketball-admin

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about SportsPress for Basketball