
wp-championship Security & Risk Analysis
wordpress.org/plugins/wp-championshipwp-championship is a plugin for wordpress letting you play a guessing game of a tournament e.g. soccer
Is wp-championship Safe to Use in 2026?
Generally Safe
Score 98/100wp-championship has a strong security track record. Known vulnerabilities have been patched promptly.
The 'wp-championship' plugin v11.0 exhibits a mixed security posture. While it demonstrates good practices in using prepared statements for all SQL queries and a high percentage of output escaping, several significant concerns remain. The presence of 6 unprotected AJAX handlers, which represent a substantial portion of the total entry points, creates a direct attack surface that could be exploited for unauthorized actions. Furthermore, the taint analysis revealed 6 high-severity flows with unsanitized paths, indicating potential for injection vulnerabilities despite the use of prepared statements. The plugin's vulnerability history shows a pattern of high-severity issues, specifically CSRF and SQL Injection, although it currently has no unpatched CVEs. The past vulnerabilities suggest recurring weaknesses that attackers might try to exploit, especially in conjunction with the identified unprotected AJAX endpoints. Overall, while some security fundamentals are strong, the unprotected entry points and high-severity taint flows demand immediate attention to mitigate potential risks.
Key Concerns
- Unprotected AJAX handlers
- High severity unsanitized taint flows
- Past High severity SQL Injection vulnerabilities
- Past Cross-Site Request Forgery vulnerabilities
wp-championship Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
wp-championship <= 9.2 - Multiple Cross-Site Request Forgery Vulnerabilities
wp-championship < 5.9 - SQL Injection
wp-championship Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
wp-championship Attack Surface
AJAX Handlers 11
Shortcodes 11
WordPress Hooks 20
Scheduled Events 1
Maintenance & Trust
wp-championship Maintenance & Trust
Maintenance Signals
Community Trust
wp-championship Alternatives
AnWP Football Leagues
football-leagues-by-anwppro
A complete solution for any football site. Knockout and round-robin competitions, player profiles and statistics, squads, standings and stadiums.
Football Pool
football-pool
Add some game-day fun to your WordPress site! Let users predict match results, earn points, and go head-to-head in a fantasy sports pool.
CyberPress
cyberpress
Manage eSport Tournaments, Matches, Teams and Players.
Achievements sports league
joomsport-achievements
Sports plugin for motor racing, athletics, aquatics, gymnastics, golf, running, cycling, skiing, poker and similar sports. Manage your league with us!
MSTW Schedules & Scoreboards
mstw-schedules-scoreboards
Manages multiple sports team schedules and scoreboards. Displays schedule tables, schedule sliders, scoreboards, and countdown timers.
wp-championship Developer Profile
6 plugins · 6K total installs
How We Detect wp-championship
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-championship/jquery.tooltip.js/wp-content/plugins/wp-championship/jquery.tablesorter.min.js/wp-content/plugins/wp-championship/jquery.tablesorter.min.js/wp-content/plugins/wp-championship/cs-stats.js/wp-content/plugins/wp-championship/jquery.tooltip.js/wp-content/plugins/wp-championship/cs-admin.jswp-championship/wp-championship-default.css?ver=wp-championship/wp-championship.css?ver=wp-championship/jquery.tablesorter.min.js?ver=2.0.3wp-championship/cs-stats.js?ver=9999wp-championship/jquery.tooltip.js?ver=9999wp-championship/cs-admin.js?ver=9999HTML / DOM Fingerprints
wpc-tippform-trwpc-tippform-thwpc-tippform-td<!-- just return the css link --><!-- INIT --><!-- end of wp championship --><!-- wp championship version number -->+3 moredata-wpc-ajaxurlwpcobj[cs-usertipp][cs-userstats][cs-stats1][cs-stats2]