StatsFC Top Scorers Security & Risk Analysis

wordpress.org/plugins/statsfc-top-scorers

This widget will place a live football top scorers table in your website.

30 active installs v3.0.1 PHP + WP 3.3+ Updated Jun 21, 2023
footballpremier-leaguesoccerwidget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is StatsFC Top Scorers Safe to Use in 2026?

Generally Safe

Score 85/100

StatsFC Top Scorers has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The "statsfc-top-scorers" plugin v3.0.1 exhibits a mixed security posture. On the positive side, there are no recorded CVEs, no dangerous functions detected, and all SQL queries are properly prepared. File operations and external HTTP requests are also absent, which reduces potential attack vectors. However, several areas raise concerns. The plugin has 55% of its output properly escaped, indicating a potential for cross-site scripting (XSS) vulnerabilities where unsanitized data could be rendered directly in the browser. Furthermore, the taint analysis revealed 2 flows with unsanitized paths, which, while not flagged as critical or high severity, still represent a risk for path traversal or local file inclusion vulnerabilities if these paths are user-controlled. The lack of nonce checks and capability checks on its single shortcode entry point is a significant weakness, allowing potentially unauthorized actions or data manipulation through its shortcode.

While the plugin has no known vulnerability history, this does not guarantee future security. The presence of unescaped outputs and unsanitized paths, coupled with a lack of authorization checks on its primary entry point, presents a notable risk. Developers should prioritize addressing the output escaping and taint flow issues, and critically, implement proper nonce and capability checks on the shortcode to mitigate potential security exploits.

Key Concerns

  • Unescaped output (55% proper)
  • Taint flows with unsanitized paths (2 total)
  • Shortcode lacks nonce/capability checks
Vulnerabilities
None known

StatsFC Top Scorers Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

StatsFC Top Scorers Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

StatsFC Top Scorers Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
13
16 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

55% escaped29 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
widget (statsfc-top-scorers.php:202)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

StatsFC Top Scorers Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[statsfc-top-scorers] statsfc-top-scorers.php:299
WordPress Hooks 2
actionwp_print_footer_scriptsstatsfc-top-scorers.php:272
actionwidgets_initstatsfc-top-scorers.php:295
Maintenance & Trust

StatsFC Top Scorers Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedJun 21, 2023
PHP min version
Downloads5K

Community Trust

Rating100/100
Number of ratings1
Active installs30
Developer Profile

StatsFC Top Scorers Developer Profile

Will Woodward

14 plugins · 370 total installs

84
trust score
Avg Security Score
86/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect StatsFC Top Scorers

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/statsfc-top-scorers/css/style.css/wp-content/plugins/statsfc-top-scorers/js/script.js
Script Paths
/wp-content/plugins/statsfc-top-scorers/js/script.js
Version Parameters
statsfc-top-scorers/css/style.css?ver=statsfc-top-scorers/js/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
statsfc-top-scorers-widgetstatsfc-scorers-tablestatsfc-scorers-rowstatsfc-scorers-playerstatsfc-scorers-teamstatsfc-scorers-goalsstatsfc-scorers-image
HTML Comments
<!-- statsfc-top-scorers widget --><!-- /statsfc-top-scorers widget -->
Data Attributes
data-plugin-name="statsfc-top-scorers"data-plugin-version="3.0.1"
JS Globals
var statsfcTopScorersPluginUrl = '
Shortcode Output
[statsfc_top_scorers
FAQ

Frequently Asked Questions about StatsFC Top Scorers