WP Russian Horoscope Security & Risk Analysis

wordpress.org/plugins/wp-russian-horoscope

Данный плагин выводит актуальный гороскоп на текущее число календаря. Имеет несколько категорий и генератор в админпанели.

20 active installs v1.1 PHP + WP 3.6.0+ Updated May 8, 2016
astrologerastrologyhoroscopesign-of-the-zodiacstar
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP Russian Horoscope Safe to Use in 2026?

Generally Safe

Score 85/100

WP Russian Horoscope has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The wp-russian-horoscope plugin v1.1 presents a mixed security posture. On the positive side, it demonstrates good practices by avoiding dangerous functions, using prepared statements for all SQL queries, and having no known historical vulnerabilities. The attack surface is also minimal, with only one entry point (a shortcode) and no AJAX handlers or REST API routes that appear to be unprotected. However, a significant concern arises from the output escaping analysis, where 100% of the identified outputs are not properly escaped. This indicates a potential for cross-site scripting (XSS) vulnerabilities, where malicious scripts could be injected and executed in the user's browser. The absence of nonce checks and the single capability check on the shortcode, while not outright dangerous in isolation, reduce the overall robustness of the input validation. The plugin also makes an external HTTP request, which could be a vector if the external resource is compromised or if the request handling itself is not secure. The lack of any taint analysis flows might be due to the limited scope of the analysis or the absence of complex data manipulation within the plugin. Overall, while the plugin is free of known critical vulnerabilities and uses secure database practices, the unescaped output represents a tangible risk that requires immediate attention.

Key Concerns

  • All identified outputs are unescaped
  • External HTTP request without explicit security review
  • Shortcode exists without specific nonce check
Vulnerabilities
None known

WP Russian Horoscope Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WP Russian Horoscope Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

0% escaped1 total outputs
Attack Surface

WP Russian Horoscope Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[ruhoroscope] index.php:69
WordPress Hooks 1
actionadmin_menuindex.php:70
Maintenance & Trust

WP Russian Horoscope Maintenance & Trust

Maintenance Signals

WordPress version tested4.5.33
Last updatedMay 8, 2016
PHP min version
Downloads3K

Community Trust

Rating94/100
Number of ratings3
Active installs20
Developer Profile

WP Russian Horoscope Developer Profile

Glaswr

1 plugin · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP Russian Horoscope

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
wrapcard
Shortcode Output
ОбщийЛюбовныйМобильныйАвтомобильный
FAQ

Frequently Asked Questions about WP Russian Horoscope