
StatsFC Squad Selector Security & Risk Analysis
wordpress.org/plugins/statsfc-squad-selectorThis widget will place a bespoke squad selector on your website.
Is StatsFC Squad Selector Safe to Use in 2026?
Generally Safe
Score 85/100StatsFC Squad Selector has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'statsfc-squad-selector' plugin v1.2.2 demonstrates a generally good security posture based on the provided static analysis. The absence of any recorded CVEs, critical taint flows, dangerous functions, file operations, or external HTTP requests is highly positive. The use of prepared statements for all SQL queries is a significant strength, mitigating SQL injection risks. However, there are areas for improvement. A substantial portion (29%) of output is not properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is directly reflected in the output without sufficient sanitization. Additionally, the lack of nonce checks and capability checks for the identified shortcode is a concern, as it could potentially be exploited by unauthenticated or unauthorized users through direct calls or malicious manipulation of the shortcode's behavior, thereby increasing the attack surface. While the vulnerability history is clean, suggesting good development practices so far, the unescaped outputs and lack of robust authentication/authorization on the shortcode represent potential entry points that should be addressed proactively.
Key Concerns
- Unescaped output detected
- Missing nonce check on shortcode
- Missing capability check on shortcode
StatsFC Squad Selector Security Vulnerabilities
StatsFC Squad Selector Code Analysis
Output Escaping
StatsFC Squad Selector Attack Surface
Shortcodes 1
WordPress Hooks 1
Maintenance & Trust
StatsFC Squad Selector Maintenance & Trust
Maintenance Signals
Community Trust
StatsFC Squad Selector Alternatives
Soccer Widgets – Football Results & Rankings
webeki-soccer-scores
Soccer Widgets: use shortcodes to deliver updated soccer data like various table rankings and football results by competition.
StatsFC Table
statsfc-table
This widget will place a football league table on your website.
StatsFC Fixtures
statsfc-fixtures
This widget will display a list of football fixtures on your website, for a chosen competition or team.
StatsFC Results
statsfc-results
This widget will place list of football results in your website.
StatsFC Live
statsfc-live
This widget will display live football scores on your website, for a chosen competition or team.
StatsFC Squad Selector Developer Profile
13 plugins · 360 total installs
How We Detect StatsFC Squad Selector
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/statsfc-squad-selector/script.js/wp-content/plugins/statsfc-squad-selector/script.jsstatsfc-squad-selector/script.js?ver=HTML / DOM Fingerprints
id="statsfc-squad-selector"<iframe id="statsfc-squad-selector" src="https://xi.statsfc.com/" width="" height="750" scrolling="no" frameborder="no"></iframe>