UORS External Course List Security & Risk Analysis

wordpress.org/plugins/uors-external-course-list

This plugin adds a "Quick Reserve" widget to your wordpress weblog sidebar. With this widget you can display a list of services that you pr …

10 active installs v0.1.4 PHP + WP 3.0.1+ Updated May 30, 2012
agendaclassclassroomcounsellorinstructoroffice
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is UORS External Course List Safe to Use in 2026?

Generally Safe

Score 85/100

UORS External Course List has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 13yr ago
Risk Assessment

The "uors-external-course-list" plugin v0.1.4 exhibits a mixed security posture. On the positive side, static analysis reveals a lack of identified dangerous functions, file operations, external HTTP requests, and SQL queries that are not using prepared statements. The plugin also has no recorded vulnerabilities (CVEs) in its history, suggesting a history of responsible development or a lack of widespread testing that would uncover issues. However, a significant concern is the complete lack of output escaping for all identified outputs. This indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, as any data displayed to users that originates from user input or external sources is not being properly sanitized, leaving the door open for malicious code injection. The absence of nonce and capability checks, while not explicitly flagged as risky given the current attack surface, also points to a potential weakness if new entry points are introduced without proper security considerations. The absence of any identified taint flows and a small attack surface (zero entry points) are good indicators, but the unescaped output remains a critical vulnerability that needs immediate attention.

Key Concerns

  • Output escaping is not implemented
  • No nonce checks detected
  • No capability checks detected
Vulnerabilities
None known

UORS External Course List Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

UORS External Course List Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped5 total outputs
Attack Surface

UORS External Course List Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionwidgets_initUORS_externalcourselist.php:145
Maintenance & Trust

UORS External Course List Maintenance & Trust

Maintenance Signals

WordPress version tested3.3.2
Last updatedMay 30, 2012
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

UORS External Course List Developer Profile

uniwits

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect UORS External Course List

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/uors-external-course-list/style.css
Script Paths
http://reserv.uniwits.com/cp

HTML / DOM Fingerprints

CSS Classes
widget-containerwidget_meta
FAQ

Frequently Asked Questions about UORS External Course List