WoW Progress Security & Risk Analysis

wordpress.org/plugins/wow-progress

A widget that helps to display guild raid progress.

30 active installs v1.23.0 PHP 5.6+ WP 3.0+ Updated Aug 17, 2025
guildprogresswarcraftworld-of-warcraftwow
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is WoW Progress Safe to Use in 2026?

Generally Safe

Score 100/100

WoW Progress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7mo ago
Risk Assessment

The 'wow-progress' v1.23.0 plugin exhibits a generally strong security posture based on the provided static analysis. It successfully avoids common pitfalls such as direct SQL queries, large attack surfaces, and external HTTP requests. The absence of known CVEs and a clean vulnerability history further bolster this positive assessment, suggesting a well-maintained and secure plugin.

However, a significant concern arises from the low percentage of properly escaped output (9%). With 32 total outputs, only a small fraction are being secured, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. While the static analysis did not identify any specific taint flows or dangerous functions that leverage these potential XSS flaws, the presence of numerous unescaped outputs creates a substantial attack vector that could be exploited by malicious actors. The lack of nonce and capability checks across its entry points, although currently empty, also represents a potential future risk if functionality is added without these security measures.

In conclusion, while 'wow-progress' v1.23.0 has demonstrated good practices in several key security areas and boasts a clean vulnerability record, the widespread issue of unescaped output is a critical weakness. This makes it susceptible to XSS attacks. Developers should prioritize addressing these output escaping issues to mitigate this significant risk.

Key Concerns

  • Low output escaping percentage
  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
None known

WoW Progress Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WoW Progress Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
29
3 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

9% escaped32 total outputs
Attack Surface

WoW Progress Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionadmin_initinc\admin.php:13
actionadmin_menuinc\admin.php:19
actionwp_enqueue_scriptswowprogress.php:64
actionadmin_enqueue_scriptswowprogress.php:65
actionplugins_loadedwowprogress.php:497
actionwidgets_initwowprogress.php:503
Maintenance & Trust

WoW Progress Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedAug 17, 2025
PHP min version5.6
Downloads22K

Community Trust

Rating88/100
Number of ratings5
Active installs30
Developer Profile

WoW Progress Developer Profile

martinek

1 plugin · 30 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WoW Progress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wow-progress/wowprogress.css/wp-content/plugins/wow-progress/wowprogress.js
Script Paths
//wow.zamimg.com/widgets/power.js/wp-content/plugins/wow-progress/wowprogress.js
Version Parameters
wowprogress?ver=wowprogress_theme?ver=

HTML / DOM Fingerprints

CSS Classes
wowprogressexpansion_headexpansionraid
HTML Comments
<!-- .expansion -->
Data Attributes
data-progress-count
JS Globals
wowprogress
Shortcode Output
<div id="wowprogress">
FAQ

Frequently Asked Questions about WoW Progress