Air Horn Security & Risk Analysis

wordpress.org/plugins/air-horn

Air horn for WordPress.

10 active installs v0.0.1 PHP + WP 3.0.1+ Updated Jan 29, 2015
airairhornfunnyhornprank
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Air Horn Safe to Use in 2026?

Generally Safe

Score 85/100

Air Horn has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The 'air-horn' plugin v0.0.1 presents a mixed security posture. On one hand, the absence of known CVEs and a lack of critical code signals like dangerous functions or file operations are positive indicators. The plugin also appears to be free of external HTTP requests and does not bundle any libraries, which can sometimes introduce vulnerabilities. However, there are significant concerns stemming from the static analysis. Notably, 100% of outputs are not properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. Furthermore, the complete absence of nonce checks and capability checks across all identified entry points (though there are currently none) suggests a lack of robust authentication and authorization mechanisms, which could become a major weakness if the attack surface grows. The current lack of any identified attack vectors is a strength, but the underlying coding practices regarding output handling and authorization are concerning and leave the plugin vulnerable to future exploits should new entry points be added.

Key Concerns

  • Output not properly escaped
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Air Horn Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Air Horn Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped1 total outputs
Attack Surface

Air Horn Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionwp_loginairhorn.php:11
actionadmin_footerairhorn.php:12
actionadmin_bar_menuairhorn.php:13
actionadmin_enqueue_scriptsairhorn.php:14
Maintenance & Trust

Air Horn Maintenance & Trust

Maintenance Signals

WordPress version tested4.1.0
Last updatedJan 29, 2015
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

Air Horn Developer Profile

Jason Stallings

4 plugins · 50 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Air Horn

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/air-horn/howler.min.js/wp-content/plugins/air-horn/airhorn.js/wp-content/plugins/air-horn/airhorn.mp3
Script Paths
airhorn.js

HTML / DOM Fingerprints

CSS Classes
airhorn_button
Data Attributes
data-airhorn_button
JS Globals
airhorn_varshowler
Shortcode Output
<audio autoplay><source src="type="audio/mpeg"></audio>
FAQ

Frequently Asked Questions about Air Horn