
StatsFC Top Scorers Security & Risk Analysis
wordpress.org/plugins/statsfc-top-scorersThis widget will place a live football top scorers table in your website.
Is StatsFC Top Scorers Safe to Use in 2026?
Generally Safe
Score 85/100StatsFC Top Scorers has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "statsfc-top-scorers" plugin v3.0.1 exhibits a mixed security posture. On the positive side, there are no recorded CVEs, no dangerous functions detected, and all SQL queries are properly prepared. File operations and external HTTP requests are also absent, which reduces potential attack vectors. However, several areas raise concerns. The plugin has 55% of its output properly escaped, indicating a potential for cross-site scripting (XSS) vulnerabilities where unsanitized data could be rendered directly in the browser. Furthermore, the taint analysis revealed 2 flows with unsanitized paths, which, while not flagged as critical or high severity, still represent a risk for path traversal or local file inclusion vulnerabilities if these paths are user-controlled. The lack of nonce checks and capability checks on its single shortcode entry point is a significant weakness, allowing potentially unauthorized actions or data manipulation through its shortcode.
While the plugin has no known vulnerability history, this does not guarantee future security. The presence of unescaped outputs and unsanitized paths, coupled with a lack of authorization checks on its primary entry point, presents a notable risk. Developers should prioritize addressing the output escaping and taint flow issues, and critically, implement proper nonce and capability checks on the shortcode to mitigate potential security exploits.
Key Concerns
- Unescaped output (55% proper)
- Taint flows with unsanitized paths (2 total)
- Shortcode lacks nonce/capability checks
StatsFC Top Scorers Security Vulnerabilities
StatsFC Top Scorers Release Timeline
StatsFC Top Scorers Code Analysis
Output Escaping
Data Flow Analysis
StatsFC Top Scorers Attack Surface
Shortcodes 1
WordPress Hooks 2
Maintenance & Trust
StatsFC Top Scorers Maintenance & Trust
Maintenance Signals
Community Trust
StatsFC Top Scorers Alternatives
StatsFC Table
statsfc-table
This widget will place a football league table on your website.
StatsFC Fixtures
statsfc-fixtures
This widget will display a list of football fixtures on your website, for a chosen competition or team.
StatsFC Next Fixture
statsfc-next-fixture
This widget will show the next fixture for a Premier League team on your website.
StatsFC Results
statsfc-results
This widget will place list of football results in your website.
StatsFC Form
statsfc-form
This widget will place a current football form guide in your website.
StatsFC Top Scorers Developer Profile
14 plugins · 370 total installs
How We Detect StatsFC Top Scorers
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/statsfc-top-scorers/css/style.css/wp-content/plugins/statsfc-top-scorers/js/script.js/wp-content/plugins/statsfc-top-scorers/js/script.jsstatsfc-top-scorers/css/style.css?ver=statsfc-top-scorers/js/script.js?ver=HTML / DOM Fingerprints
statsfc-top-scorers-widgetstatsfc-scorers-tablestatsfc-scorers-rowstatsfc-scorers-playerstatsfc-scorers-teamstatsfc-scorers-goalsstatsfc-scorers-image<!-- statsfc-top-scorers widget --><!-- /statsfc-top-scorers widget -->data-plugin-name="statsfc-top-scorers"data-plugin-version="3.0.1"var statsfcTopScorersPluginUrl = '[statsfc_top_scorers