WOW Server Status Widget Security & Risk Analysis

wordpress.org/plugins/wow-server-status-widget

Easily add WOW Server Status 4.1 badge to your wordpress site by just a few clicks.

10 active installs v1.0.13 PHP + WP 2.8+ Updated Apr 4, 2016
realmserverwarcraftworld-of-warcraftwow
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WOW Server Status Widget Safe to Use in 2026?

Generally Safe

Score 85/100

WOW Server Status Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The "wow-server-status-widget" plugin v1.0.13 exhibits a mixed security posture. On the positive side, it shows no known vulnerabilities (CVEs) and no critical or high severity taint flows. The absence of dangerous functions and the consistent use of prepared statements for its SQL queries are also good indicators of secure coding practices.

However, significant concerns arise from the static analysis. The plugin has a complete lack of proper output escaping, meaning that any data processed and displayed by the plugin is vulnerable to Cross-Site Scripting (XSS) attacks. Furthermore, the absence of nonce checks and capability checks, especially considering it handles file operations, leaves it open to various security weaknesses that could be exploited if an attacker can inject malicious data or trigger these operations without proper authorization. The zero-day attack surface is concerning, but it might be misleading given the other identified weaknesses that can be exploited through other means.

In conclusion, while the plugin has a clean vulnerability history and uses prepared statements, the critical issue of universally unescaped output presents a high risk. Coupled with the lack of authorization checks on file operations and no nonce checks, this plugin requires immediate attention to address potential XSS and other injection vulnerabilities. The lack of a broader attack surface reported might be due to the plugin's specific functionality, but the identified code-level weaknesses are substantial.

Key Concerns

  • 0% of outputs properly escaped
  • No nonce checks
  • No capability checks
  • File operations present without auth checks
Vulnerabilities
None known

WOW Server Status Widget Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

WOW Server Status Widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
32
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
4
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped32 total outputs
Attack Surface

WOW Server Status Widget Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_initinc\admin.php:5
actionadmin_menuinc\admin.php:6
actionwidgets_initwow-server-status-widget.php:21
filterplugin_action_linkswow-server-status-widget.php:52
Maintenance & Trust

WOW Server Status Widget Maintenance & Trust

Maintenance Signals

WordPress version tested4.5.33
Last updatedApr 4, 2016
PHP min version
Downloads8K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

WOW Server Status Widget Developer Profile

Freeman Man

3 plugins · 40 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WOW Server Status Widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about WOW Server Status Widget