
StatsFC Table Security & Risk Analysis
wordpress.org/plugins/statsfc-tableThis widget will place a football league table on your website.
Is StatsFC Table Safe to Use in 2026?
Generally Safe
Score 85/100StatsFC Table has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The statsfc-table v2.2.1 plugin exhibits a generally good security posture based on the provided static analysis. It does not utilize dangerous functions, perform file operations, make external HTTP requests, or contain known vulnerabilities. The use of prepared statements for all SQL queries is a strong security practice. However, there are notable concerns regarding output escaping, with less than half of the detected outputs being properly escaped, indicating a potential for cross-site scripting (XSS) vulnerabilities. Additionally, the absence of nonce checks and capability checks across all entry points, including the single shortcode, is a significant weakness. While no critical or high severity taint flows were identified in the limited analysis, the presence of unsanitized paths in the analyzed flows is a red flag that warrants further investigation.
The plugin's history of zero known CVEs is positive, suggesting a good track record. However, this is in the context of a limited attack surface and the potential for unaddressed vulnerabilities due to the lack of robust security checks like nonce and capability checks. The absence of vulnerabilities in the past does not guarantee future security, especially if the identified weaknesses in output escaping and authorization are exploited.
In conclusion, while the plugin has strengths in its SQL handling and lack of external dependencies or dangerous functions, the significant percentage of unescaped output and the complete lack of nonce/capability checks on its shortcode create a tangible risk. The taint analysis, though limited, also points to potential issues with unsanitized paths. Addressing the output escaping and implementing proper authorization checks on the shortcode are critical steps to improve its security.
Key Concerns
- Unescaped output detected
- No nonce checks on entry points
- No capability checks on entry points
- Unsanitized paths in taint flows
StatsFC Table Security Vulnerabilities
StatsFC Table Code Analysis
Output Escaping
Data Flow Analysis
StatsFC Table Attack Surface
Shortcodes 1
WordPress Hooks 2
Maintenance & Trust
StatsFC Table Maintenance & Trust
Maintenance Signals
Community Trust
StatsFC Table Alternatives
StatsFC Fixtures
statsfc-fixtures
This widget will display a list of football fixtures on your website, for a chosen competition or team.
StatsFC Results
statsfc-results
This widget will place list of football results in your website.
StatsFC Next Fixture
statsfc-next-fixture
This widget will show the next fixture for a Premier League team on your website.
StatsFC Form
statsfc-form
This widget will place a current football form guide in your website.
StatsFC Top Assisters
statsfc-top-assisters
This widget will place a live football top assisters table in your website.
StatsFC Table Developer Profile
13 plugins · 360 total installs
How We Detect StatsFC Table
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/statsfc-table/css/statsfc-table.css/wp-content/plugins/statsfc-table/js/statsfc-table.js/wp-content/plugins/statsfc-table/js/statsfc-table.jsstatsfc-table/css/statsfc-table.css?ver=statsfc-table/js/statsfc-table.js?ver=HTML / DOM Fingerprints
statsfc-table-widgetstatsfc-table-competitionstatsfc-table-groupstatsfc-table-seasonstatsfc-table-typestatsfc-table-highlightstatsfc-table-rowsstatsfc-table-date+5 more<!-- StatsFC League Table -->data-competitiondata-groupdata-seasondata-typedata-highlightdata-rows+5 morestatsfc_table_params[statsfc_table