StatsFC Fixtures Security & Risk Analysis

wordpress.org/plugins/statsfc-fixtures

This widget will display a list of football fixtures on your website, for a chosen competition or team.

50 active installs v3.1.0 PHP + WP 3.3+ Updated Apr 22, 2024
fixturesfootballpremier-leaguesoccerwidget
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is StatsFC Fixtures Safe to Use in 2026?

Generally Safe

Score 92/100

StatsFC Fixtures has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "statsfc-fixtures" v3.1.0 plugin demonstrates a generally good security posture with several positive indicators. The absence of known CVEs and the use of prepared statements for all SQL queries are significant strengths. The limited attack surface, with only one shortcode and no unprotected AJAX handlers or REST API routes, further contributes to a lower risk profile. However, there are areas for improvement. The 52% proper output escaping suggests that a notable portion of outputs are not being sanitized, which could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is involved in these unsanitized outputs. Additionally, the presence of 2 flows with unsanitized paths in the taint analysis, while not classified as critical or high, warrants attention as these could potentially be exploited for directory traversal or other file-related attacks if not properly handled. The lack of nonce and capability checks on the identified entry point (the shortcode) is a concern, as it means there are no built-in protections against unauthorized use or abuse of the shortcode's functionality.

Key Concerns

  • Unsanitized paths in taint analysis
  • Low output escaping percentage
  • Missing nonce check on entry point
  • Missing capability check on entry point
Vulnerabilities
None known

StatsFC Fixtures Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

StatsFC Fixtures Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
20
22 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

52% escaped42 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
widget (statsfc-fixtures.php:253)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

StatsFC Fixtures Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[statsfc-fixtures] statsfc-fixtures.php:354
WordPress Hooks 2
actionwp_print_footer_scriptsstatsfc-fixtures.php:327
actionwidgets_initstatsfc-fixtures.php:350
Maintenance & Trust

StatsFC Fixtures Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedApr 22, 2024
PHP min version
Downloads8K

Community Trust

Rating100/100
Number of ratings2
Active installs50
Developer Profile

StatsFC Fixtures Developer Profile

Will Woodward

13 plugins · 360 total installs

86
trust score
Avg Security Score
88/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect StatsFC Fixtures

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/statsfc-fixtures/statsfc-fixtures.css/wp-content/plugins/statsfc-fixtures/statsfc-fixtures.js
Script Paths
/wp-content/plugins/statsfc-fixtures/statsfc-fixtures.js
Version Parameters
statsfc-fixtures/statsfc-fixtures.css?ver=statsfc-fixtures/statsfc-fixtures.js?ver=

HTML / DOM Fingerprints

CSS Classes
statsfc-fixtures-widget
Data Attributes
data-statsfc-keydata-statsfc-competitiondata-statsfc-groupdata-statsfc-teamdata-statsfc-seasondata-statsfc-from+7 more
JS Globals
StatsFC_Fixtures
FAQ

Frequently Asked Questions about StatsFC Fixtures