
WP Russian Horoscope Security & Risk Analysis
wordpress.org/plugins/wp-russian-horoscopeДанный плагин выводит актуальный гороскоп на текущее число календаря. Имеет несколько категорий и генератор в админпанели.
Is WP Russian Horoscope Safe to Use in 2026?
Generally Safe
Score 85/100WP Russian Horoscope has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-russian-horoscope plugin v1.1 presents a mixed security posture. On the positive side, it demonstrates good practices by avoiding dangerous functions, using prepared statements for all SQL queries, and having no known historical vulnerabilities. The attack surface is also minimal, with only one entry point (a shortcode) and no AJAX handlers or REST API routes that appear to be unprotected. However, a significant concern arises from the output escaping analysis, where 100% of the identified outputs are not properly escaped. This indicates a potential for cross-site scripting (XSS) vulnerabilities, where malicious scripts could be injected and executed in the user's browser. The absence of nonce checks and the single capability check on the shortcode, while not outright dangerous in isolation, reduce the overall robustness of the input validation. The plugin also makes an external HTTP request, which could be a vector if the external resource is compromised or if the request handling itself is not secure. The lack of any taint analysis flows might be due to the limited scope of the analysis or the absence of complex data manipulation within the plugin. Overall, while the plugin is free of known critical vulnerabilities and uses secure database practices, the unescaped output represents a tangible risk that requires immediate attention.
Key Concerns
- All identified outputs are unescaped
- External HTTP request without explicit security review
- Shortcode exists without specific nonce check
WP Russian Horoscope Security Vulnerabilities
WP Russian Horoscope Code Analysis
Output Escaping
WP Russian Horoscope Attack Surface
Shortcodes 1
WordPress Hooks 1
Maintenance & Trust
WP Russian Horoscope Maintenance & Trust
Maintenance Signals
Community Trust
WP Russian Horoscope Alternatives
Nine Star Ki
nine-star-ki
This tool calculates the three character numbers of the nine-star-ki astrology based on the (birth) date.
EZ Horoscope Professional
ez-horoscope
Astrologically accurate horoscopes with cosmic insights, advice, birth charts, and AI voice agents for chatting about readings.
The Daily Horoscope
the-daily-horoscope
Add The Daily Horoscope Plugin to your widgets, posts and pages. Select your sign and read your daily horoscope.
Ephemeris
ephemeris
Adds a sidebar widget that display from the astrological sky the sun sign, the moon sign and the moon phase.
Monthly Horoscopes
monthly-horoscopes
Add up to 12 months of sun sign monthly horoscopes to your sites pages and posts pages with this free and easy to install WordPress plugin.
WP Russian Horoscope Developer Profile
1 plugin · 20 total installs
How We Detect WP Russian Horoscope
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
wrapcardОбщийЛюбовныйМобильныйАвтомобильный