
WoWTag Widget Security & Risk Analysis
wordpress.org/plugins/wowtag-widgetEnter your Character's name and realm and a WoWTag displaying your avatar, name, race, class, guild, level and title will be placed on your site.
Is WoWTag Widget Safe to Use in 2026?
Generally Safe
Score 85/100WoWTag Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wowtag-widget" v0.2.2B plugin presents a mixed security posture. On the positive side, there are no known CVEs associated with this plugin, and the code analysis reveals no dangerous functions, no external HTTP requests, and SQL queries are properly prepared, which are excellent indicators of security awareness in development. The absence of any identified CVEs over time suggests a generally stable and well-maintained plugin.
However, significant concerns arise from the code signals and taint analysis. The most critical issue is the extremely low percentage of properly escaped output (4%). This indicates a high probability of cross-site scripting (XSS) vulnerabilities, as user-supplied data is likely being rendered directly into the browser without proper sanitization. Furthermore, the taint analysis shows a flow with an unsanitized path, which, while not classified as critical or high severity in this analysis, is a strong signal for potential security weaknesses, especially when combined with the output escaping issues. The lack of nonce and capability checks on potential entry points (even though the attack surface is reported as zero) is also a concern, as it suggests that any future expansion of functionality without these checks could introduce vulnerabilities.
Key Concerns
- Low percentage of properly escaped output
- Flow with unsanitized path
- Missing nonce checks
- Missing capability checks
WoWTag Widget Security Vulnerabilities
WoWTag Widget Release Timeline
WoWTag Widget Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WoWTag Widget Attack Surface
WordPress Hooks 2
Maintenance & Trust
WoWTag Widget Maintenance & Trust
Maintenance Signals
Community Trust
WoWTag Widget Alternatives
WoW Armory
wow-armory
Easily displays your character's stats from the Armory.
WoW Progress
wow-progress
A widget that helps to display guild raid progress.
WOW Recruitment Widget
wow-recruit-widget
A widget that helps to display recruitment message of a World of Warcraft guild, also can be used for other games that have different classes.
WoWpi
wowpi
The WoWpi plugin allows you to retrieve data from Battle.net API regarding your World of Warcraft character and/or guild.
Game Dev Quotes
game-dev-quotes
Simple shortcodes to style game developer quotes as they are on the developers site.
WoWTag Widget Developer Profile
3 plugins · 30 total installs
How We Detect WoWTag Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wowtag-widget/wowtag.js/wp-content/plugins/wowtag-widget/wowtag.jsHTML / DOM Fingerprints
wowtagid="wowtag-widget"wT