
StatsFC Fixtures Security & Risk Analysis
wordpress.org/plugins/statsfc-fixturesThis widget will display a list of football fixtures on your website, for a chosen competition or team.
Is StatsFC Fixtures Safe to Use in 2026?
Generally Safe
Score 92/100StatsFC Fixtures has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "statsfc-fixtures" v3.1.0 plugin demonstrates a generally good security posture with several positive indicators. The absence of known CVEs and the use of prepared statements for all SQL queries are significant strengths. The limited attack surface, with only one shortcode and no unprotected AJAX handlers or REST API routes, further contributes to a lower risk profile. However, there are areas for improvement. The 52% proper output escaping suggests that a notable portion of outputs are not being sanitized, which could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is involved in these unsanitized outputs. Additionally, the presence of 2 flows with unsanitized paths in the taint analysis, while not classified as critical or high, warrants attention as these could potentially be exploited for directory traversal or other file-related attacks if not properly handled. The lack of nonce and capability checks on the identified entry point (the shortcode) is a concern, as it means there are no built-in protections against unauthorized use or abuse of the shortcode's functionality.
Key Concerns
- Unsanitized paths in taint analysis
- Low output escaping percentage
- Missing nonce check on entry point
- Missing capability check on entry point
StatsFC Fixtures Security Vulnerabilities
StatsFC Fixtures Code Analysis
Output Escaping
Data Flow Analysis
StatsFC Fixtures Attack Surface
Shortcodes 1
WordPress Hooks 2
Maintenance & Trust
StatsFC Fixtures Maintenance & Trust
Maintenance Signals
Community Trust
StatsFC Fixtures Alternatives
StatsFC Next Fixture
statsfc-next-fixture
This widget will show the next fixture for a Premier League team on your website.
StatsFC Table
statsfc-table
This widget will place a football league table on your website.
StatsFC Results
statsfc-results
This widget will place list of football results in your website.
StatsFC Live
statsfc-live
This widget will display live football scores on your website, for a chosen competition or team.
StatsFC Form
statsfc-form
This widget will place a current football form guide in your website.
StatsFC Fixtures Developer Profile
13 plugins · 360 total installs
How We Detect StatsFC Fixtures
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/statsfc-fixtures/statsfc-fixtures.css/wp-content/plugins/statsfc-fixtures/statsfc-fixtures.js/wp-content/plugins/statsfc-fixtures/statsfc-fixtures.jsstatsfc-fixtures/statsfc-fixtures.css?ver=statsfc-fixtures/statsfc-fixtures.js?ver=HTML / DOM Fingerprints
statsfc-fixtures-widgetdata-statsfc-keydata-statsfc-competitiondata-statsfc-groupdata-statsfc-teamdata-statsfc-seasondata-statsfc-from+7 moreStatsFC_Fixtures