
The Soccer Stats Security & Risk Analysis
wordpress.org/plugins/the-soccer-statsUltimate tool for your football (soccer) team site.
Is The Soccer Stats Safe to Use in 2026?
Generally Safe
Score 85/100The Soccer Stats has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "the-soccer-stats" v1.08 plugin exhibits a mixed security posture. On the positive side, it shows strong practices in database interaction, with all SQL queries utilizing prepared statements, and no file operations or external HTTP requests are detected. The absence of known historical vulnerabilities (CVEs) and a lack of critical taint analysis findings are also encouraging signs. However, there are significant security concerns stemming from its attack surface. A substantial number of AJAX handlers (8 out of 22) lack proper authentication checks, creating potential entry points for unauthorized actions. While the taint analysis did not reveal critical or high-severity issues, the presence of unsanitized paths in all analyzed flows, even if flagged as low severity, warrants attention as it could be exploited in conjunction with other weaknesses. The limited number of nonce and capability checks on AJAX handlers further exacerbates the risk posed by the unprotected entry points.
Key Concerns
- Unprotected AJAX handlers
- Unsanitized paths in taint flows
- Limited capability checks on AJAX
- Limited nonce checks on AJAX
The Soccer Stats Security Vulnerabilities
The Soccer Stats Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
The Soccer Stats Attack Surface
AJAX Handlers 22
WordPress Hooks 17
Maintenance & Trust
The Soccer Stats Maintenance & Trust
Maintenance Signals
Community Trust
The Soccer Stats Alternatives
Soccer Engine – Soccer Plugin for WordPress
soccer-engine-lite
Soccer Engine is a plugin that lets bloggers and clubs add results, fixtures, match commentaries, transfers, and a wide range of stats to articles.
Player Transfers for SportsPress
player-transfers-for-sportspress
Manage and display player transfers seamlessly within SportsPress. Enhance your sports website with structured transfer records and team history.
Football Club Manager
football-club-manager
Easily manage your amateur football club. Create team pages, player info, and integrate match data!
SportsPress – Sports Club & League Manager
sportspress
SportsPress is an extendable all-in-one sports data plugin that helps sports clubs set up and manage a league or club site quickly and easily.
AnWP Football Leagues
football-leagues-by-anwppro
A complete solution for any football site. Knockout and round-robin competitions, player profiles and statistics, squads, standings and stadiums.
The Soccer Stats Developer Profile
3 plugins · 930 total installs
How We Detect The Soccer Stats
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/the-soccer-stats/css/tss-bootstrap.css/wp-content/plugins/the-soccer-stats/plugins/bootstrap/bootstrap.min.js/wp-content/plugins/the-soccer-stats/js/admin-main.js/wp-content/plugins/the-soccer-stats/plugins/select2/select2.min.js/wp-content/plugins/the-soccer-stats/css/tss-admin.css/wp-content/plugins/the-soccer-stats/plugins/select2/select2.min.css/wp-content/plugins/the-soccer-stats/css/tss-default.css/wp-content/plugins/the-soccer-stats/plugins/font-awesome/css/font-awesome.min.css+2 morethe-soccer-stats/tss-bootstrap.css?ver=the-soccer-stats/plugins/bootstrap/bootstrap.min.js?ver=the-soccer-stats/js/admin-main.js?ver=the-soccer-stats/plugins/select2/select2.min.js?ver=the-soccer-stats/css/tss-admin.css?ver=the-soccer-stats/plugins/select2/select2.min.css?ver=the-soccer-stats/css/tss-default.css?ver=the-soccer-stats/plugins/font-awesome/css/font-awesome.min.css?ver=the-soccer-stats/plugins/tablesorter/jquery.tablesorter.min.js?ver=the-soccer-stats/js/main.js?ver=HTML / DOM Fingerprints
ajaxurl