
WoW Armory Security & Risk Analysis
wordpress.org/plugins/wow-armoryEasily displays your character's stats from the Armory.
Is WoW Armory Safe to Use in 2026?
Generally Safe
Score 85/100WoW Armory has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wow-armory" plugin v8.4.3 exhibits a mixed security posture. On the positive side, it has no known historical vulnerabilities (CVEs) and its single SQL query is properly prepared. The attack surface is minimal, with no AJAX handlers or REST API routes, and the sole shortcode appears to have no direct unauthenticated entry points based on the provided data. However, significant concerns arise from the static code analysis. A critical finding is that 100% of its output is not properly escaped, posing a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. Furthermore, the plugin lacks nonce checks and capability checks entirely, which are fundamental security mechanisms for protecting against various attacks, especially if any hidden or unintended entry points exist or are introduced in future updates. The presence of a flow with unsanitized paths, even if not flagged as critical or high severity, warrants attention due to its inherent risk. The absence of any recorded vulnerabilities in its history might suggest a lack of rigorous security testing or that potential vulnerabilities have not yet been discovered or exploited.
Key Concerns
- 0% output escaping
- No nonce checks
- No capability checks
- Flows with unsanitized paths
WoW Armory Security Vulnerabilities
WoW Armory Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WoW Armory Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
WoW Armory Maintenance & Trust
Maintenance Signals
Community Trust
WoW Armory Alternatives
WoW Guild
wow-guild
Easily displays your Guild's Roster from the armory
WoWpi
wowpi
The WoWpi plugin allows you to retrieve data from Battle.net API regarding your World of Warcraft character and/or guild.
Warcraft Bundle
warcraft-bundle
Warcraft Bundle for WordPress. World of Warcraft collection pages and widgets for WordPress.
WoWpi Guild
wowpi-guild
You want a proper World of Warcraft's guild website but you don't know how? Look no further. This is the plugin for your guild's needs.
HTML Special Characters Helper
html-special-characters-helper
Admin widget on the Add/Edit Post pages for inserting HTML encodings of special characters into the post.
WoW Armory Developer Profile
2 plugins · 20 total installs
How We Detect WoW Armory
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wow-armory/css/style.csswow-armory/css/style.css?ver=HTML / DOM Fingerprints
widget_wow_armorywowhead