viversum: Mondphase Security & Risk Analysis

wordpress.org/plugins/viversum-mondphase

viversum Mondphase als Widget

10 active installs v1.0c PHP + WP 3.5+ Updated Aug 28, 2013
daily-horoscopehoroscopehoroskoptageshoroskopviversum
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is viversum: Mondphase Safe to Use in 2026?

Generally Safe

Score 85/100

viversum: Mondphase has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12yr ago
Risk Assessment

The "viversum-mondphase" v1.0c plugin exhibits a mixed security posture. While it demonstrates good practices by not exposing a significant attack surface through AJAX, REST API, shortcodes, or cron events, and all its SQL queries utilize prepared statements, there are several notable concerns. The presence of the `create_function` is a significant red flag due to its potential for arbitrary code execution. Furthermore, the complete lack of output escaping across all 15 identified outputs is a critical vulnerability, exposing the plugin to cross-site scripting (XSS) attacks. The absence of any nonce checks or capability checks on the limited entry points further exacerbates this risk, as any user could potentially trigger unintended actions. The plugin's vulnerability history is clean, with no recorded CVEs, which might suggest a lack of targeted attacks or a relatively new codebase. However, this clean history should not be mistaken for robust security, given the significant flaws identified in the static analysis.

Key Concerns

  • Dangerous function detected (create_function)
  • All outputs are unescaped
  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
None known

viversum: Mondphase Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

viversum: Mondphase Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
0 prepared
Unescaped Output
15
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

create_functionadd_action('widgets_init', create_function('', 'return register_widget("viversumMondphase");'));viversum-mondphase.php:213

Output Escaping

0% escaped15 total outputs
Attack Surface

viversum: Mondphase Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionwidgets_initviversum-mondphase.php:204
actionwidgets_initviversum-mondphase.php:213
Maintenance & Trust

viversum: Mondphase Maintenance & Trust

Maintenance Signals

WordPress version tested3.5.2
Last updatedAug 28, 2013
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

viversum: Mondphase Developer Profile

viversum

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect viversum: Mondphase

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Script Paths
/wp-content/plugins/viversum-mondphase/js/viv-moonphase.js
Version Parameters
viversum-mondphase/js/viv-moonphase.js?ver=

HTML / DOM Fingerprints

CSS Classes
viversumMondphase
Data Attributes
id="viversumMondphase-*
JS Globals
viversumMondphase
Shortcode Output
<script type="text/javascript" src="http://vivget.com/viv/loader/moonphasesimple/loader.js"></script><script type="text/javascript" src="http://vivget.com/viv/loader/moonphase/color/<noscript><a href="http://www.viversum.de/" rel="nofollow">viversum Lebensberatung</a></noscript>
FAQ

Frequently Asked Questions about viversum: Mondphase