
StatsFC Next Fixture Security & Risk Analysis
wordpress.org/plugins/statsfc-next-fixtureThis widget will show the next fixture for a Premier League team on your website.
Is StatsFC Next Fixture Safe to Use in 2026?
Generally Safe
Score 85/100StatsFC Next Fixture has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "statsfc-next-fixture" v3.0.1 plugin exhibits a generally good security posture due to the absence of known CVEs and a lack of dangerous functions. The code analysis reveals a positive trend in using prepared statements for SQL queries, indicating an effort to prevent SQL injection vulnerabilities. However, there are notable concerns regarding output escaping, with over half of outputs not being properly escaped, posing a risk of Cross-Site Scripting (XSS) vulnerabilities. The taint analysis identified two flows with unsanitized paths, which, although not classified as critical or high severity in this analysis, represent potential avenues for attack if not addressed. The lack of nonce checks and capability checks on entry points, specifically the identified shortcode, is a significant weakness, leaving the plugin susceptible to unauthorized actions if an attacker can trigger this shortcode. The vulnerability history being clear of any past issues is a positive indicator of development attention, but the current code weaknesses necessitate careful consideration.
Key Concerns
- Significant portion of outputs not properly escaped
- Taint analysis shows unsanitized paths
- No nonce checks on entry points (shortcode)
- No capability checks on entry points (shortcode)
StatsFC Next Fixture Security Vulnerabilities
StatsFC Next Fixture Code Analysis
Output Escaping
Data Flow Analysis
StatsFC Next Fixture Attack Surface
Shortcodes 1
WordPress Hooks 2
Maintenance & Trust
StatsFC Next Fixture Maintenance & Trust
Maintenance Signals
Community Trust
StatsFC Next Fixture Alternatives
StatsFC Fixtures
statsfc-fixtures
This widget will display a list of football fixtures on your website, for a chosen competition or team.
StatsFC Table
statsfc-table
This widget will place a football league table on your website.
StatsFC Results
statsfc-results
This widget will place list of football results in your website.
StatsFC Live
statsfc-live
This widget will display live football scores on your website, for a chosen competition or team.
StatsFC Form
statsfc-form
This widget will place a current football form guide in your website.
StatsFC Next Fixture Developer Profile
13 plugins · 360 total installs
How We Detect StatsFC Next Fixture
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/statsfc-next-fixture/statsfc-next-fixture.js/wp-content/plugins/statsfc-next-fixture/statsfc-next-fixture.css/wp-content/plugins/statsfc-next-fixture/statsfc-next-fixture.jsstatsfc-next-fixture/statsfc-next-fixture.js?ver=statsfc-next-fixture/statsfc-next-fixture.css?ver=HTML / DOM Fingerprints
statsfc-next-fixturedata-statsfc-nextfixture-iddata-statsfc-nextfixture-keydata-statsfc-nextfixture-teamdata-statsfc-nextfixture-competitiondata-statsfc-nextfixture-datedata-statsfc-nextfixture-timezone+2 moreSTATSFC_NEXTFIXTURE_ID<div class="statsfc-next-fixture" data-statsfc-nextfixture-id="" data-statsfc-nextfixture-key="" data-statsfc-nextfixture-team="" data-statsfc-nextfixture-competition="