
Warcraft Bundle Security & Risk Analysis
wordpress.org/plugins/warcraft-bundleWarcraft Bundle for WordPress. World of Warcraft collection pages and widgets for WordPress.
Is Warcraft Bundle Safe to Use in 2026?
Generally Safe
Score 100/100Warcraft Bundle has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "warcraft-bundle" v2.3.2 plugin presents a mixed security posture. On the positive side, it demonstrates good practices in handling SQL queries, exclusively using prepared statements, and its vulnerability history is clean with no known CVEs. The static analysis also indicates a minimal attack surface in terms of AJAX handlers and REST API routes, with no unprotected entry points identified in these areas. However, several concerning signals exist within the code analysis. The presence of "dangerous functions" like create_function is a red flag, as it can lead to security vulnerabilities if not handled with extreme care. Furthermore, a significant portion of output (63%) is not properly escaped, posing a risk of Cross-Site Scripting (XSS) vulnerabilities. The taint analysis, while limited in scope with only two flows analyzed, revealed unsanitized paths, which, if not handled correctly, could lead to security issues. The complete absence of nonce checks and capability checks on its identified entry points (shortcodes, cron events) is a significant weakness, leaving these functionalities potentially vulnerable to unauthorized access or execution. While the plugin has no recorded history of vulnerabilities, the internal code analysis reveals potential weaknesses that could be exploited if not addressed.
Key Concerns
- Unsanitized paths in taint analysis
- Dangerous functions (create_function) used
- Significant unescaped output (37% escaped)
- No nonce checks on entry points
- No capability checks on entry points
Warcraft Bundle Security Vulnerabilities
Warcraft Bundle Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Warcraft Bundle Attack Surface
Shortcodes 1
WordPress Hooks 6
Scheduled Events 1
Maintenance & Trust
Warcraft Bundle Maintenance & Trust
Maintenance Signals
Community Trust
Warcraft Bundle Alternatives
WoW Progress
wow-progress
A widget that helps to display guild raid progress.
WOW Recruitment Widget
wow-recruit-widget
A widget that helps to display recruitment message of a World of Warcraft guild, also can be used for other games that have different classes.
WoWpi
wowpi
The WoWpi plugin allows you to retrieve data from Battle.net API regarding your World of Warcraft character and/or guild.
WoW Armory
wow-armory
Easily displays your character's stats from the Armory.
WoW Breaking News
wow-breaking-news
This plugin will let you add a widget on your wordpress site displaying the in-game breaking news that you can se while logging in to World of Warcraf …
Warcraft Bundle Developer Profile
7 plugins · 70 total installs
How We Detect Warcraft Bundle
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/warcraft-bundle/css/admin.css/wp-content/plugins/warcraft-bundle/css/frontend.css/wp-content/plugins/warcraft-bundle/js/jquery.tables.min.js/wp-content/plugins/warcraft-bundle/js/jquery.countdown.js/wp-content/plugins/warcraft-bundle/js/basic-jquery-slider.min.js/wp-content/plugins/warcraft-bundle/js/jquery.freeow.min.js/wp-content/plugins/warcraft-bundle/js/jPages.min.js/wp-content/plugins/warcraft-bundle/js/jquery.qtip.min.js+2 more/wp-content/plugins/warcraft-bundle/js/jquery.tables.min.js/wp-content/plugins/warcraft-bundle/js/jquery.countdown.js/wp-content/plugins/warcraft-bundle/js/basic-jquery-slider.min.js/wp-content/plugins/warcraft-bundle/js/jquery.freeow.min.js/wp-content/plugins/warcraft-bundle/js/jPages.min.js/wp-content/plugins/warcraft-bundle/js/jquery.qtip.min.js+1 morewarcraft-bundle/css/admin.css?ver=warcraft-bundle/css/frontend.css?ver=warcraft-bundle/js/jquery.tables.min.js?ver=warcraft-bundle/js/jquery.countdown.js?ver=warcraft-bundle/js/basic-jquery-slider.min.js?ver=warcraft-bundle/js/jquery.freeow.min.js?ver=warcraft-bundle/js/jPages.min.js?ver=warcraft-bundle/js/jquery.qtip.min.js?ver=warcraft-bundle/js/warcraft-qtip-dark.js?ver=warcraft-bundle/css/jquery.qtip.min.css?ver=HTML / DOM Fingerprints
<!-- Copyright Laurent (KwarK) Bertrand (email : kwark@allwebtuts.net) --><!-- php class by Thomas Andersen http://www.acoon.dk/ --><!-- You can not remove these comments such as authors informations. --><!-- This program is free software; you can redistribute it and/or modify -->+38 moredata-wb-guild-namedata-wb-realm-namedata-wb-guild-rankdata-wb-player-rankdata-wb-player-namedata-wb-player-class+1 morewb_plugin_urlwowarmory