
StatsFC Score Predictor Security & Risk Analysis
wordpress.org/plugins/statsfc-score-predictorThis widget will place a score predictor for a football team's matches on your website.
Is StatsFC Score Predictor Safe to Use in 2026?
Generally Safe
Score 85/100StatsFC Score Predictor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "statsfc-score-predictor" plugin v3.1.0 exhibits a generally positive security posture with some notable areas of concern. The absence of known CVEs and unpatched vulnerabilities is a strong indicator of good past security practices. The code analysis reveals a very limited attack surface with only one shortcode entry point and no AJAX handlers or REST API routes exposed without proper checks, which is commendable. Furthermore, the plugin utilizes prepared statements for all SQL queries, mitigating SQL injection risks effectively.
However, a significant weakness lies in the output escaping, where only 50% of outputs are properly escaped. This opens the door to potential Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not handled carefully before being displayed. The taint analysis, while having a small number of flows, identified two flows with unsanitized paths, which, despite not being flagged as critical or high severity, warrant attention. The complete lack of nonce and capability checks on the identified entry points, while the attack surface is currently small, represents a future risk should the plugin's functionality expand.
In conclusion, the plugin benefits from a clean vulnerability history and robust SQL handling. The primary risks stem from the insufficient output escaping and the presence of unsanitized paths in taint flows. The absence of nonce and capability checks on existing entry points is a potential vulnerability waiting to be exploited if the plugin's exposure increases. Addressing the output escaping and investigating the unsanitized paths are crucial next steps.
Key Concerns
- Unsanitized paths in taint flows (2 flows)
- Output escaping only 50% proper
- No nonce checks on entry points
- No capability checks on entry points
StatsFC Score Predictor Security Vulnerabilities
StatsFC Score Predictor Code Analysis
Output Escaping
Data Flow Analysis
StatsFC Score Predictor Attack Surface
Shortcodes 1
WordPress Hooks 2
Maintenance & Trust
StatsFC Score Predictor Maintenance & Trust
Maintenance Signals
Community Trust
StatsFC Score Predictor Alternatives
StatsFC Prediction League
statsfc-prediction-league
This widget will place a prediction league for a competition of your choice on your website.
StatsFC Live
statsfc-live
This widget will display live football scores on your website, for a chosen competition or team.
Soccer Widgets – Football Results & Rankings
webeki-soccer-scores
Soccer Widgets: use shortcodes to deliver updated soccer data like various table rankings and football results by competition.
StatsFC Table
statsfc-table
This widget will place a football league table on your website.
StatsFC Fixtures
statsfc-fixtures
This widget will display a list of football fixtures on your website, for a chosen competition or team.
StatsFC Score Predictor Developer Profile
13 plugins · 360 total installs
How We Detect StatsFC Score Predictor
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/statsfc-score-predictor/js/statsfc-score-predictor.jsstatsfc-score-predictor/js/statsfc-score-predictor.js?ver=HTML / DOM Fingerprints
statsfc-score-predictor-widgetdata-widget-iddata-keydata-teamdata-competitiondata-datedata-show-match-details+5 morestatsfc_score_predictor_ajax_object<div id="statsfc-score-predictor-widget-statsfc-score-predictor-widget