
Ustream Status Security & Risk Analysis
wordpress.org/plugins/ustream-statusDisplay the online/offline status of a Ustream channel
Is Ustream Status Safe to Use in 2026?
Generally Safe
Score 85/100Ustream Status has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "ustream-status" v3.0.1 plugin exhibits a generally strong security posture based on the provided static analysis. The plugin boasts a minimal attack surface with only one shortcode entry point, and notably, zero AJAX handlers or REST API routes that are unprotected by authentication or permission checks. Furthermore, all identified SQL queries are correctly implemented using prepared statements, mitigating the risk of SQL injection vulnerabilities. The absence of any recorded CVEs, historical or current, is also a positive indicator of the plugin's security track record.
However, there are areas that warrant attention. A significant concern is the low percentage of properly escaped output (43%). This indicates a substantial risk of Cross-Site Scripting (XSS) vulnerabilities, as user-provided or dynamic content may be rendered directly in the browser without sufficient sanitization. Additionally, the lack of any observed nonce checks or capability checks, combined with the minimal number of file operations, suggests that the plugin may not be robustly protected against certain types of attacks that rely on these security mechanisms. While the taint analysis found no flows, the limited scope of analysis (0 flows analyzed) means this doesn't provide a high degree of confidence.
In conclusion, while the plugin benefits from a small attack surface and a clean vulnerability history, the high proportion of unescaped output presents a critical security weakness that requires immediate remediation. The absence of nonce and capability checks also contributes to a less secure overall design. Addressing the output escaping issues should be the top priority to improve the plugin's security.
Key Concerns
- Low percentage of properly escaped output
- Missing nonce checks
- Missing capability checks
Ustream Status Security Vulnerabilities
Ustream Status Release Timeline
Ustream Status Code Analysis
Output Escaping
Ustream Status Attack Surface
Shortcodes 1
WordPress Hooks 2
Maintenance & Trust
Ustream Status Maintenance & Trust
Maintenance Signals
Community Trust
Ustream Status Alternatives
Twitcasting Status
twitcasting-status
Display the online/offline status of a Twitcasting channel.
Custom Order Status Manager for WooCommerce
bp-custom-order-status-for-woocommerce
Custom Order Status Manager for WooCommerce plugin allows you to create, delete and edit order statuses to better control the flow of your orders.
Custom Order Status for WooCommerce
custom-order-statuses-woocommerce
Custom Order Status for WooCommerce allows you to create and manage order statuses. It improves order management & overall order workflow.
WPCargo Track & Trace
wpcargo
WPCargo is a track & trace system for courier, courier script, parcel, balikbayan system, shipment and transportation management system, ideal sol …
Advanced Custom Stock Status
woo-custom-stock-status
Write the custom stock status with different colors for each woocommerce product, to show in product details and listing pages.
Ustream Status Developer Profile
2 plugins · 20 total installs
How We Detect Ustream Status
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
<!--Form--><!--/Form--><!-- Ustream Status starts here --><!-- TRANSIENT STARTS HERE -->+6 moreustream:channel_id[ustream-status online= offline= channel=