
StatsFC Form Security & Risk Analysis
wordpress.org/plugins/statsfc-formThis widget will place a current football form guide in your website.
Is StatsFC Form Safe to Use in 2026?
Generally Safe
Score 85/100StatsFC Form has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'statsfc-form' plugin v3.0.1 exhibits a generally good security posture with no recorded vulnerabilities and a limited attack surface consisting of a single shortcode. The plugin also demonstrates positive development practices by exclusively using prepared statements for SQL queries and not performing file operations or external HTTP requests, which significantly reduces common attack vectors. However, there are notable areas of concern that detract from its overall security.
A significant weakness identified is the lack of proper output escaping, with only 53% of outputs being correctly sanitized. This leaves the plugin susceptible to Cross-Site Scripting (XSS) vulnerabilities, particularly if user-supplied data is rendered without adequate escaping within the shortcode's output. Furthermore, the analysis reveals two taint flows with unsanitized paths, although they are not classified as critical or high severity. The absence of nonce checks and capability checks on its entry points is also a concern, as it implies that unauthorized users could potentially trigger unintended functionality or manipulate data, especially given the presence of a shortcode that could be invoked by various users.
In conclusion, while the plugin benefits from a clean vulnerability history and responsible SQL handling, the unescaped outputs and lack of authentication/authorization checks on its single entry point present clear security risks. Addressing the output escaping and implementing appropriate checks would greatly enhance its security.
Key Concerns
- Insufficient output escaping (47% unescaped)
- Taint flows with unsanitized paths detected
- Missing nonce checks on entry points
- Missing capability checks on entry points
StatsFC Form Security Vulnerabilities
StatsFC Form Code Analysis
Output Escaping
Data Flow Analysis
StatsFC Form Attack Surface
Shortcodes 1
WordPress Hooks 2
Maintenance & Trust
StatsFC Form Maintenance & Trust
Maintenance Signals
Community Trust
StatsFC Form Alternatives
StatsFC Table
statsfc-table
This widget will place a football league table on your website.
StatsFC Fixtures
statsfc-fixtures
This widget will display a list of football fixtures on your website, for a chosen competition or team.
StatsFC Results
statsfc-results
This widget will place list of football results in your website.
StatsFC Next Fixture
statsfc-next-fixture
This widget will show the next fixture for a Premier League team on your website.
StatsFC Top Assisters
statsfc-top-assisters
This widget will place a live football top assisters table in your website.
StatsFC Form Developer Profile
13 plugins · 360 total installs
How We Detect StatsFC Form
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/statsfc-form/css/style.css/wp-content/plugins/statsfc-form/js/statsfc-form.jsstatsfc-form/css/style.css?ver=statsfc-form/js/statsfc-form.js?ver=HTML / DOM Fingerprints
statsfc-widget-containerstatsfc-tablestatsfc-team-highlight<!-- BEGIN STATSFC FORM WIDGET --><!-- END STATSFC FORM WIDGET -->data-statsfc-keydata-statsfc-competitiondata-statsfc-teamdata-statsfc-yeardata-statsfc-datedata-statsfc-highlight+4 moreStatsFC[statsfc_form