W2O Football Fans Admin Color Schemes Security & Risk Analysis

wordpress.org/plugins/w2o-football-fans-admin-color-schemes

Admin Color Schemes for Football Fans

10 active installs v1.2 PHP + WP 4.0+ Updated Jul 31, 2018
admin-coloradmin-color-schemescolor-schemesfootball-team-colorsw2o
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is W2O Football Fans Admin Color Schemes Safe to Use in 2026?

Generally Safe

Score 85/100

W2O Football Fans Admin Color Schemes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The plugin "w2o-football-fans-admin-color-schemes" v1.2 exhibits a mixed security posture. On the positive side, it demonstrates good practices by avoiding dangerous functions, making no external HTTP requests, and utilizing prepared statements for all SQL queries. Furthermore, its vulnerability history is clean, with no known CVEs, suggesting a history of secure development. The absence of a significant attack surface with AJAX handlers, REST API routes, shortcodes, or cron events is also a strength.

However, there are significant concerns arising from the static analysis. The most critical finding is that 100% of the output is not properly escaped. This presents a high risk of Cross-Site Scripting (XSS) vulnerabilities, as unsanitized data displayed to users could contain malicious scripts. Additionally, the taint analysis revealed one flow with an unsanitized path, indicating a potential for unauthorized data access or manipulation, although it was not classified as critical or high severity. The lack of nonce checks and capability checks on any entry points, while the attack surface is zero, means if any were added in the future without proper checks, they would be unprotected.

In conclusion, while the plugin benefits from a clean vulnerability history and some secure coding practices like prepared statements, the prevalent lack of output escaping is a major security weakness that severely undermines its overall security. The presence of an unsanitized path, even if not critical, warrants attention. The plugin's security could be significantly improved by addressing the output escaping and the identified taint flow.

Key Concerns

  • 100% of outputs unescaped
  • Flow with unsanitized path
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

W2O Football Fans Admin Color Schemes Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

W2O Football Fans Admin Color Schemes Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
15
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped15 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<w2o_fbfn_acs.css> (core\w2o_fbfn_acs.css.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

W2O Football Fans Admin Color Schemes Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_initcore\class-acs.php:10
actionadmin_headcore\class-acs.php:11
actionadmin_menucore\class-acs.php:12
actionadmin_menucore\class-acs.php:13
Maintenance & Trust

W2O Football Fans Admin Color Schemes Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedJul 31, 2018
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings3
Active installs10
Developer Profile

W2O Football Fans Admin Color Schemes Developer Profile

Shishir Raj Adhikari

2 plugins · 110 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect W2O Football Fans Admin Color Schemes

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about W2O Football Fans Admin Color Schemes