
Advanced Sermons Security & Risk Analysis
wordpress.org/plugins/advanced-sermonsElevate your church's digital outreach with audio/video sermons, organized speakers, and series management.
Is Advanced Sermons Safe to Use in 2026?
Generally Safe
Score 96/100Advanced Sermons has a strong security track record. Known vulnerabilities have been patched promptly.
The "advanced-sermons" plugin v3.7 exhibits a mixed security posture. While it demonstrates good practices in areas like SQL query sanitization and a complete lack of unpatched vulnerabilities, several significant concerns arise from the static analysis and its historical vulnerability record. The presence of unprotected AJAX handlers directly contributes to a larger attack surface, as these can be exploited by unauthenticated users. The taint analysis, though showing no critical or high severity flows, did reveal all analyzed flows with unsanitized paths, which warrants attention for potential indirect vulnerabilities or chained exploits. The historical data indicates a pattern of medium severity Cross-Site Scripting (XSS) vulnerabilities, suggesting a recurring issue with input handling and output escaping despite the otherwise decent proportion of properly escaped outputs. The plugin's strength lies in its prompt patching of past vulnerabilities, but the ongoing presence of unprotected entry points and historical XSS trends indicate that vigilance is still required.
Key Concerns
- Unprotected AJAX handlers
- Flows with unsanitized paths
- 5 historical medium severity XSS CVEs
- Only 52% output escaping
Advanced Sermons Security Vulnerabilities
CVEs by Year
Severity Breakdown
5 total CVEs
Advanced Sermons <= 3.6 - Authenticated (Contributor+) Stored Cross-Site Scripting
Advanced Sermons <= 3.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
Advanced Sermons <= 3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
Advanced Sermons <= 3.1 - Reflected Cross-Site Scripting via s
Advanced Sermons <= 3.2 - Reflected Cross-Site Scripting
Advanced Sermons Code Analysis
Output Escaping
Data Flow Analysis
Advanced Sermons Attack Surface
AJAX Handlers 3
WordPress Hooks 113
Maintenance & Trust
Advanced Sermons Maintenance & Trust
Maintenance Signals
Community Trust
Advanced Sermons Alternatives
Church Content – Sermons, Events and More
church-theme-content
Provides an interface for managing sermons, events, people and locations. A compatible theme is required for presenting content from these church-cent …
Church Admin
church-admin
Organise and communicate church life, with associated Android and iOS app for your congregation.
Church Social
church-social
This plugin allows churches to display content from their Church Social account on their WordPress website.
SermonPress
sermonpress
This is a fully customizable sermon library plugin. It comes complete with the ability to add audio and video sermons.
Sel Church Sermon
sel-church-sermons
This plugin created for official church themes from Selthemes.com
Advanced Sermons Developer Profile
2 plugins · 3K total installs
How We Detect Advanced Sermons
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/advanced-sermons/include/js/asp_admin_script.js/wp-content/plugins/advanced-sermons/styling/css/asp_admin_style.css/wp-content/plugins/advanced-sermons/styling/css/asp_public_style.css/wp-content/plugins/advanced-sermons/include/js/asp_public_script.jsadvanced-sermons/include/js/asp_admin_script.js?ver=advanced-sermons/styling/css/asp_admin_style.css?ver=advanced-sermons/styling/css/asp_public_style.css?ver=advanced-sermons/include/js/asp_public_script.js?ver=HTML / DOM Fingerprints
asp-post-thumbnailasp-sermon-detailsasp-sermon-titleasp-sermon-dateasp-sermon-speakerasp-sermon-seriesasp-sermon-topicsasp-sermon-book+14 more<!-- Exit if accessed directly --><!-- Flush permalinks when the plugin is activated --><!-- The helpers functions for repeated functionalities --><!-- The core plugin file that is used to define internationalization, hooks and functions -->+9 moredata-sermon-iddata-speaker-iddata-series-iddata-topic-iddata-book-iddata-player-id+2 moreasp_admin_dataadvanced_sermons_ajax_object/wp-json/advanced-sermons/v1/settings/wp-json/advanced-sermons/v1/sermons[advanced_sermons][sermon_list][sermon_player][sermon_details]