
Soccer Widgets – Football Results & Rankings Security & Risk Analysis
wordpress.org/plugins/webeki-soccer-scoresSoccer Widgets: use shortcodes to deliver updated soccer data like various table rankings and football results by competition.
Is Soccer Widgets – Football Results & Rankings Safe to Use in 2026?
Generally Safe
Score 85/100Soccer Widgets – Football Results & Rankings has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The webeki-soccer-scores plugin v1.3 exhibits a mixed security posture. While it demonstrates good practices in output escaping, with 98% of outputs properly handled, and has no recorded vulnerability history, several significant concerns are raised by the static analysis.
The plugin's attack surface includes two AJAX handlers, both of which lack authentication checks. This is a critical weakness, as it allows any authenticated user to potentially trigger these handlers, leading to security vulnerabilities. Furthermore, the analysis reveals that 100% of SQL queries within the plugin do not utilize prepared statements. This is a substantial risk, as it makes the plugin highly susceptible to SQL injection attacks.
The absence of any recorded CVEs and its clean vulnerability history is a positive sign, suggesting a lack of previously discovered critical flaws. However, the identified security weaknesses in the code itself, particularly the unauthenticated AJAX endpoints and the widespread use of raw SQL queries, present a considerable risk that outweighs the historical safety. The plugin has strengths in output handling but significant vulnerabilities in input validation and database interaction that need immediate attention.
Key Concerns
- AJAX handlers without authentication
- SQL queries without prepared statements
- No nonce checks
- No capability checks
Soccer Widgets – Football Results & Rankings Security Vulnerabilities
Soccer Widgets – Football Results & Rankings Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Soccer Widgets – Football Results & Rankings Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
Soccer Widgets – Football Results & Rankings Maintenance & Trust
Maintenance Signals
Community Trust
Soccer Widgets – Football Results & Rankings Alternatives
No alternatives data available yet.
Soccer Widgets – Football Results & Rankings Developer Profile
2 plugins · 130 total installs
How We Detect Soccer Widgets – Football Results & Rankings
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/webeki-soccer-scores/admin/css/style.css/wp-content/plugins/webeki-soccer-scores/admin/js/script.js/wp-content/plugins/webeki-soccer-scores/frontend/css/style.css/wp-content/plugins/webeki-soccer-scores/admin/js/script.jsHTML / DOM Fingerprints
isLeagueid="sswidget-generator"id="sswidgetlanguage"id="sswidgetdatatype"id="sswidgettournament"id="sswidgetgroup"id="ShortcodePrev"+1 more[soccerstats