Springest Partners for WordPress Security & Risk Analysis

wordpress.org/plugins/springest-partners

Display relevant courses and trainings from Springest on your website.

10 active installs v0.1.4 PHP + WP 3.0+ Updated Jan 3, 2013
affiliatecoursesnetworkpartnersspringest
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Springest Partners for WordPress Safe to Use in 2026?

Generally Safe

Score 85/100

Springest Partners for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 13yr ago
Risk Assessment

The "springest-partners" plugin v0.1.4 exhibits a generally strong security posture based on the provided static analysis. The absence of known CVEs and the consistent use of prepared statements for all SQL queries are significant strengths. Furthermore, the plugin demonstrates good practice by implementing nonce and capability checks, and importantly, no unprotected AJAX handlers, REST API routes, or shortcodes were identified, minimizing the direct attack surface. However, a notable concern arises from the taint analysis, which indicates two flows with unsanitized paths. While these did not reach critical or high severity, they represent potential vectors for exploitation if malicious input is not properly handled. The low percentage of properly escaped output (11%) is another area that warrants attention, as it could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is rendered without adequate sanitization. The single file operation and external HTTP request, while not inherently risky, should be reviewed for context and potential misuse. In conclusion, the plugin has a solid foundation with no known historical vulnerabilities and good input validation practices for SQL. The primary areas for improvement are addressing the identified unsanitized paths and significantly enhancing output escaping to mitigate XSS risks.

Key Concerns

  • Unsanitized paths found in taint analysis
  • Low percentage of properly escaped output
Vulnerabilities
None known

Springest Partners for WordPress Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Springest Partners for WordPress Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

Springest Partners for WordPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
42 prepared
Unescaped Output
96
12 escaped
Nonce Checks
1
Capability Checks
1
File Operations
1
External Requests
1
Bundled Libraries
0

SQL Query Safety

100% prepared42 total queries

Output Escaping

11% escaped108 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
SA_settings (springest-admin.php:49)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Springest Partners for WordPress Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 18
filterwp_footerinc/SpringestApi.inc.php:42
filteradmin_footerinc/SpringestApi.inc.php:43
actionadmin_noticesinc/SpringestHelper.inc.php:26
actionwp_headinc/SpringestHelper.inc.php:35
filterthe_titleinc/SpringestHelper.inc.php:312
filterthe_contentinc/SpringestHelper.inc.php:314
filterwp_titleinc/SpringestHelper.inc.php:316
actionadmin_menuspringest-admin.php:6
actionadmin_menuspringest-admin.php:7
actionadmin_menuspringest-admin.php:8
actionadmin_headspringest-admin.php:9
actionadmin_headspringest-admin.php:10
actionadmin_initspringest.php:61
actioninitspringest.php:72
filterrewrite_rules_arrayspringest.php:82
filterquery_varsspringest.php:83
actionwidgets_initspringest.php:86
actionwpspringest.php:89
Maintenance & Trust

Springest Partners for WordPress Maintenance & Trust

Maintenance Signals

WordPress version tested3.5.2
Last updatedJan 3, 2013
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Springest Partners for WordPress Developer Profile

Super Interactive

2 plugins · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Springest Partners for WordPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/springest-partners/springest-admin.css/wp-content/plugins/springest-partners/springest-admin.js

HTML / DOM Fingerprints

JS Globals
api_url
FAQ

Frequently Asked Questions about Springest Partners for WordPress