VereinOnline.org Security & Risk Analysis

wordpress.org/plugins/vereinonline

Zeigt VereinOnline-Inhalte in WordPress an. http://www.vereinonline.org/

200 active installs v3.0.7 PHP + WP 3.0.3+ Updated Dec 1, 2025
mitgliederonlinesoftwareveranstaltungenverein
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is VereinOnline.org Safe to Use in 2026?

Generally Safe

Score 100/100

VereinOnline.org has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The "vereinonline" v3.0.7 plugin presents a generally good security posture based on the provided static analysis. The absence of dangerous functions, raw SQL queries, and file operations is a strong positive indicator. The high percentage of properly escaped output further suggests diligent development practices. However, several areas warrant attention. The significant number of shortcodes (16) represents a substantial attack surface, and the lack of explicit capability checks or nonce checks on any of these entry points, while noted as having no unprotected entry points, is a concerning oversight. If any of these shortcodes handle user-supplied data without proper validation and authorization, they could become a vector for abuse. The presence of external HTTP requests also introduces a potential risk if the target endpoints are not secured or if the data sent to them is not properly sanitized and validated.

The vulnerability history is exceptionally clean, with no recorded CVEs. This indicates a history of good security practices or successful remediation of past issues. However, the absence of vulnerabilities does not equate to absolute security, especially given the potential attack surface mentioned above. The lack of taint analysis data is also a limitation, as it prevents a deeper understanding of how data flows through the plugin and whether sensitive information could be mishandled. In conclusion, while the plugin demonstrates strengths in its handling of core security features like SQL and output escaping, the substantial number of shortcodes without apparent robust authorization checks is a notable weakness that could be exploited.

Key Concerns

  • No capability checks on entry points
  • No nonce checks on entry points
  • External HTTP requests (2)
  • Unescaped output (8%)
Vulnerabilities
None known

VereinOnline.org Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

VereinOnline.org Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
48 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

92% escaped52 total outputs
Attack Surface

VereinOnline.org Attack Surface

Entry Points16
Unprotected0

Shortcodes 16

[vereinonline_kalender] vereinonline.php:65
[vereinonline_termin] vereinonline.php:66
[vereinonline_termine_filter] vereinonline.php:67
[vereinonline_termine] vereinonline.php:68
[vereinonline_gruppentermine] vereinonline.php:69
[vereinonline_bildergalerien] vereinonline.php:70
[vereinonline_newsletter] vereinonline.php:71
[vereinonline_news] vereinonline.php:72
[vereinonline_shop] vereinonline.php:73
[vereinonline_mitglieder] vereinonline.php:74
[vereinonline_request] vereinonline.php:75
[vereinonline_subscribe] vereinonline.php:76
[vereinonline_spenden] vereinonline.php:77
[vereinonline_gruppen] vereinonline.php:78
[vereinonline_list] vereinonline.php:79
[vereinonline_for] vereinonline.php:80
WordPress Hooks 7
filterpre_update_option_vereinonline_setting_pwdvereinonline.php:40
filterthe_contentvereinonline.php:60
filterwidget_textvereinonline.php:61
filterauthenticatevereinonline.php:83
actionadmin_initvereinonline.php:84
actionwp_enqueue_scriptsvereinonline.php:85
actionwp_enqueue_scriptsvereinonline.php:86
Maintenance & Trust

VereinOnline.org Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 1, 2025
PHP min version
Downloads12K

Community Trust

Rating0/100
Number of ratings0
Active installs200
Developer Profile

VereinOnline.org Developer Profile

Dr. Thomas Fuessl

2 plugins · 210 total installs

100
trust score
Avg Security Score
100/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect VereinOnline.org

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/vereinonline/vereinonline.css/wp-content/plugins/vereinonline/vereinonline.js
Script Paths
/wp-content/plugins/vereinonline/vereinonline.js
Version Parameters
vereinonline/style.css?ver=vereinonline/script.js?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- Copyright GRITH AG --><!-- Version: 3.0.7 -->
Data Attributes
name="vereinonline_setting_url"name="vereinonline_setting_usr"name="vereinonline_setting_pwd"name="vereinonline_setting_web"name="vereinonline_setting_ath"name="vereinonline_setting_scr"+1 more
Shortcode Output
[vereinonline_kalender][vereinonline_termin][vereinonline_termine_filter][vereinonline_termine]
FAQ

Frequently Asked Questions about VereinOnline.org