
WP-Game Security & Risk Analysis
wordpress.org/plugins/wp-gameThis isn't plugin for website game. This plugin include opensource html5 games library for user visit website. This is mini game help user free s …
Is WP-Game Safe to Use in 2026?
Generally Safe
Score 85/100WP-Game has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-game v1.0 plugin exhibits a mixed security posture. On the positive side, the absence of known CVEs and a low overall attack surface suggest some level of developer diligence regarding common vulnerabilities. The plugin also appears to be free of dangerous functions and file operations, which are typically points of concern.
However, several critical security weaknesses are evident in the static analysis. The most significant concern is the complete lack of output escaping, meaning that any data outputted by the plugin is potentially vulnerable to cross-site scripting (XSS) attacks. Furthermore, the presence of a taint flow with an unsanitized path indicates a potential for data to be processed in an insecure manner, though its severity is not explicitly stated as critical or high. The absence of any capability checks or nonce checks, especially given the potential for future expansion of the attack surface, leaves the plugin vulnerable to unauthorized actions and CSRF attacks.
Given the lack of historical vulnerabilities, it's difficult to draw strong conclusions about long-term security patterns. However, the current static analysis reveals significant gaps in fundamental security practices, particularly concerning output sanitation and authorization. While the plugin currently has a minimal attack surface and no known CVEs, the identified weaknesses, if not addressed, could lead to serious security incidents as the plugin evolves or is integrated into more complex environments. The lack of output escaping and potential unsanitized taint flow are the most pressing issues.
Key Concerns
- 0% output escaping
- Taint flow with unsanitized path
- 0 nonce checks
- 0 capability checks
WP-Game Security Vulnerabilities
WP-Game Code Analysis
Output Escaping
Data Flow Analysis
WP-Game Attack Surface
WordPress Hooks 3
Maintenance & Trust
WP-Game Maintenance & Trust
Maintenance Signals
Community Trust
WP-Game Alternatives
WP Shortcode by Drimify
drimify-widget
Drimify Widget is a free WP plugin, that provides easy way to integrate your HTML5 games and interactive contents created on Drimify.com
WP Menu Icons
wp-menu-icons
WP Menu Icons allows you to add icons to your WordPress menu items.
MAS Static Content
mas-static-content
MAS Static Content is a free plugin that allows you to to create a custom post type static content and use it with shortcode.
QuadMenu – Mega Menu
quadmenu
Responsive mega menu plugin for WordPress with customizable layouts and an intuitive drag-and-drop builder.
WP Mega Menu
wp-megamenu
WordPress Mega Menu is a responsive, highly customizable drag and drop menu builder plugin. Download free WordPress megamenu plugin.
WP-Game Developer Profile
1 plugin · 10 total installs
How We Detect WP-Game
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-game/style.cssHTML / DOM Fingerprints
<!-- Add games to menu -->base href="window.requestAnimFrameaudiochannelsplay_soundgetCookiesetCookie