
WoPo Minesweeper Security & Risk Analysis
wordpress.org/plugins/wopo-minesweeperMinesweeper Game
Is WoPo Minesweeper Safe to Use in 2026?
Generally Safe
Score 85/100WoPo Minesweeper has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wopo-minesweeper plugin version 1.2.0 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The plugin has no recorded CVEs and no known vulnerabilities, which is a significant positive indicator. Furthermore, the code analysis reveals good development practices such as 100% use of prepared statements for SQL queries and a high percentage of properly escaped output. The absence of dangerous functions, file operations, and external HTTP requests further contributes to a lower risk profile.
However, there are areas that warrant attention. The lack of nonce checks on any of the entry points, particularly the single shortcode, is a concern. While there is only one identified entry point, a shortcode can still be a vector for cross-site scripting (XSS) if user-supplied data is not properly handled within it. The presence of only one capability check across all entry points also suggests a potential for privilege escalation if the shortcode's functionality is sensitive and not adequately protected. The absence of taint analysis results is noted, but this does not automatically imply security; it may simply mean no flows were detected by the tool.
In conclusion, wopo-minesweeper version 1.2.0 appears to be relatively secure due to its lack of historical vulnerabilities and sound SQL and output handling. The primary weakness lies in the absence of nonce checks and potentially insufficient capability checks on its single shortcode, which could lead to vulnerabilities if not mitigated by application-level logic. Developers should prioritize implementing nonce checks for the shortcode to protect against CSRF attacks.
Key Concerns
- Missing nonce checks on entry points
- Limited capability checks on entry points
WoPo Minesweeper Security Vulnerabilities
WoPo Minesweeper Code Analysis
Bundled Libraries
Output Escaping
WoPo Minesweeper Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
WoPo Minesweeper Maintenance & Trust
Maintenance Signals
Community Trust
WoPo Minesweeper Alternatives
WoPo Solitaire
wopo-solitaire-web-based-game-online
Solitaire Game
MorePuzzles
morepuzzles
This plugin is for those who would like to insert an interactive crossword/word-search puzzle to their page.
CTL Battleship Minesweeper Lite
ctl-battleship-minesweeper-lite
Add Battleship Minesweeper Lite to CTL Arcade Lite plugin
JRM Killboard
jrm-killboard
Display corporation kills using Killmails: sync it manually or automatically. Customizable: display your killboard the way you like it
AMG Labs Minesweeper Game
amglabs-minesweeper-game
A classic Windows-style Minesweeper game for WordPress. Relive the nostalgia of the iconic puzzle game directly on your website.
WoPo Minesweeper Developer Profile
10 plugins · 280 total installs
How We Detect WoPo Minesweeper
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wopo-minesweeper/assets/css/XP.css/wp-content/plugins/wopo-minesweeper/assets/css/98.css/wp-content/plugins/wopo-minesweeper/assets/css/main.css/wp-content/plugins/wopo-minesweeper/assets/js/main.jswopo-minesweeper/assets/css/XP.css?ver=wopo-minesweeper/assets/css/98.css?ver=wopo-minesweeper/assets/css/main.css?ver=wopo-minesweeper/assets/js/main.js?ver=HTML / DOM Fingerprints
wopo_minesweeper_styletitle-bartitle-bar-texttitle-bar-controlsbtn-minimizebtn-maximizebtn-closewindow-bodydata-custom="custom"wopoSolitaire<div id="wopo_minesweeper_window" class="window">