viversum: Tageshoroskop Security & Risk Analysis

wordpress.org/plugins/viversum-tageshoroskop

viversum Tageshoroskope für alle Sternzeichen als Widget

10 active installs v1.0f PHP + WP 3.5+ Updated Aug 28, 2013
daily-horoscopehoroscopehoroskoptageshoroskopviversum
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is viversum: Tageshoroskop Safe to Use in 2026?

Generally Safe

Score 85/100

viversum: Tageshoroskop has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12yr ago
Risk Assessment

The viversum-tageshoroskop plugin v1.0f exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by not exposing a significant attack surface, with no AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, all SQL queries are properly prepared, and there are no recorded vulnerabilities (CVEs) or known issues, suggesting a generally stable and safe development history. However, significant concerns arise from the static analysis of its code. The presence of the `create_function` function is a critical security anti-pattern due to its potential for arbitrary code execution. Additionally, a complete lack of output escaping for all 13 identified output points is highly concerning, leaving the plugin vulnerable to cross-site scripting (XSS) attacks. The absence of nonce and capability checks further exacerbates these risks by failing to implement fundamental WordPress security mechanisms for entry points that might exist, even if not explicitly listed in the attack surface.

Key Concerns

  • Use of create_function
  • 100% unescaped output
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

viversum: Tageshoroskop Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

viversum: Tageshoroskop Release Timeline

v1.0
v1.0b
v1.0c
v1.0d
v1.0e
v1.0fCurrent
Code Analysis
Analyzed Apr 16, 2026

viversum: Tageshoroskop Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
0 prepared
Unescaped Output
13
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

create_functionadd_action('widgets_init', create_function('', 'return register_widget("viversumTageshoroskop");'));viversum-tageshoroskop.php:213

Output Escaping

0% escaped13 total outputs
Attack Surface

viversum: Tageshoroskop Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionwidgets_initviversum-tageshoroskop.php:204
actionwidgets_initviversum-tageshoroskop.php:213
Maintenance & Trust

viversum: Tageshoroskop Maintenance & Trust

Maintenance Signals

WordPress version tested3.5.2
Last updatedAug 28, 2013
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

viversum: Tageshoroskop Developer Profile

viversum

2 plugins · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect viversum: Tageshoroskop

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/viversum-tageshoroskop/viv-script.js
Script Paths
http://vivget.com/viv/loader/dailyhoroscopesimple/loader.jshttp://vivget.com/viv/loader/dailyhoroscope/iconset/%d/color/%s/backgroundcolor/%s/rel/nofollow/loader.js

HTML / DOM Fingerprints

CSS Classes
color-backgroundcolor-text
Data Attributes
id="viversumTageshoroskop-widget-advanced"id="viversumTageshoroskop-widget-color_background"id="viversumTageshoroskop-widget-color_text"id="viversumTageshoroskop-widget-iconset"
JS Globals
jQuery
Shortcode Output
<script type="text/javascript" src="http://vivget.com/viv/loader/dailyhoroscopesimple/loader.js"></script><script type="text/javascript" src="http://vivget.com/viv/loader/dailyhoroscope/iconset/<noscript><a href="http://www.viversum.de/" rel="nofollow">viversum Lebensberatung</a></noscript>
FAQ

Frequently Asked Questions about viversum: Tageshoroskop