
StatsFC Top Assisters Security & Risk Analysis
wordpress.org/plugins/statsfc-top-assistersThis widget will place a live football top assisters table in your website.
Is StatsFC Top Assisters Safe to Use in 2026?
Generally Safe
Score 85/100StatsFC Top Assisters has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "statsfc-top-assisters" v2.0.1 plugin exhibits a generally positive security posture, with no recorded vulnerabilities and the absence of dangerous functions or file operations. The code adheres to good practices by utilizing prepared statements for all SQL queries and generally avoiding external HTTP requests. However, there are notable areas of concern. The static analysis reveals that only 55% of output is properly escaped, leaving a significant portion vulnerable to Cross-Site Scripting (XSS) attacks. Furthermore, the taint analysis identified two flows with unsanitized paths, which, while not flagged as critical or high severity in this specific analysis, represent potential pathways for injection vulnerabilities if not handled with extreme care in the unescaped output. The plugin's lack of nonce and capability checks on its single shortcode entry point is a significant security gap, as this shortcode could potentially be exploited by unauthenticated or unauthorized users.
Key Concerns
- Significant portion of output unescaped
- Taint flows with unsanitized paths
- Shortcode lacks nonce and capability checks
StatsFC Top Assisters Security Vulnerabilities
StatsFC Top Assisters Code Analysis
Output Escaping
Data Flow Analysis
StatsFC Top Assisters Attack Surface
Shortcodes 1
WordPress Hooks 2
Maintenance & Trust
StatsFC Top Assisters Maintenance & Trust
Maintenance Signals
Community Trust
StatsFC Top Assisters Alternatives
StatsFC Table
statsfc-table
This widget will place a football league table on your website.
StatsFC Fixtures
statsfc-fixtures
This widget will display a list of football fixtures on your website, for a chosen competition or team.
StatsFC Results
statsfc-results
This widget will place list of football results in your website.
StatsFC Next Fixture
statsfc-next-fixture
This widget will show the next fixture for a Premier League team on your website.
StatsFC Form
statsfc-form
This widget will place a current football form guide in your website.
StatsFC Top Assisters Developer Profile
13 plugins · 360 total installs
How We Detect StatsFC Top Assisters
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/statsfc-top-assisters/statsfc-top-assisters.css/wp-content/plugins/statsfc-top-assisters/statsfc-top-assisters.js/wp-content/plugins/statsfc-top-assisters/statsfc-top-assisters.jsstatsfc-top-assisters.css?ver=statsfc-top-assisters.js?ver=HTML / DOM Fingerprints
statsfc-top-assistersstatsfc-top-assisters-stats<!-- BEGIN StatsFC Top Assisters Widget --><!-- END StatsFC Top Assisters Widget -->data-statsfc-keydata-statsfc-competitiondata-statsfc-teamdata-statsfc-seasondata-statsfc-datedata-statsfc-highlight+3 morestatsfc_top_assisters<div class="statsfc-top-assisters-shortcode"></div>