WP Shredderchess Security & Risk Analysis

wordpress.org/plugins/wp-shredderchess

Widget that displays the chess puzzle from shredderchess.com.

200 active installs v1.0.7 PHP 7.0+ WP 4.1+ Updated Jan 10, 2026
boardgamechesschess-puzzlepuzzleshredderchess
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP Shredderchess Safe to Use in 2026?

Generally Safe

Score 100/100

WP Shredderchess has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The wp-shredderchess plugin v1.0.7 demonstrates a strong security posture based on the provided static analysis. The absence of a discernible attack surface, including AJAX handlers, REST API routes, shortcodes, and cron events, significantly reduces the potential entry points for attackers. Furthermore, the code signals are largely positive, with no dangerous functions identified, all SQL queries utilizing prepared statements, and a high percentage of output being properly escaped. The lack of file operations and external HTTP requests also contributes to a more secure codebase. The vulnerability history shows no recorded CVEs, indicating a clean past record for this plugin. However, the complete absence of nonce and capability checks across all identified entry points (though there are none reported) is a notable concern. If any functionality were to be added that introduced an attack surface, this would be a critical oversight. The taint analysis yielding zero flows also suggests no immediate exploitable vulnerabilities within the analyzed code. Overall, the plugin appears well-secured in its current state, but the lack of any authentication or authorization checks for potential future functionalities is a weakness that should be addressed proactively.

Key Concerns

  • No nonce checks implemented
  • No capability checks implemented
Vulnerabilities
None known

WP Shredderchess Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WP Shredderchess Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
18 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

86% escaped21 total outputs
Attack Surface

WP Shredderchess Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionwidgets_initwidget-shredderchess.php:152
actionadmin_initwidget-shredderchess.php:175
Maintenance & Trust

WP Shredderchess Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 10, 2026
PHP min version7.0
Downloads8K

Community Trust

Rating100/100
Number of ratings1
Active installs200
Developer Profile

WP Shredderchess Developer Profile

Marcel Pol

18 plugins · 82K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
1119 days
View full developer profile
Detection Fingerprints

How We Detect WP Shredderchess

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
shredderchess_widget
FAQ

Frequently Asked Questions about WP Shredderchess