
Anchor Episodes Index (Spotify for Podcasters) Security & Risk Analysis
wordpress.org/plugins/anchor-episodes-indexA lightweight plugin that allows you to output an anchor.fm podcast player on your site that includes an episode index. Just add two URL's on the …
Is Anchor Episodes Index (Spotify for Podcasters) Safe to Use in 2026?
Generally Safe
Score 99/100Anchor Episodes Index (Spotify for Podcasters) has a strong security track record. Known vulnerabilities have been patched promptly.
The "anchor-episodes-index" plugin v2.1.15 exhibits a mixed security posture. On the positive side, it demonstrates good practices with SQL queries exclusively using prepared statements and a reasonable percentage of output escaping. The absence of dangerous functions and critical or high-severity taint flows suggests a level of care in its development. However, significant concerns arise from the static analysis, particularly the presence of an AJAX handler without authentication checks. This creates a direct entry point for potential attackers. The vulnerability history is also a concern, with two known medium-severity CVEs, both related to Cross-Site Scripting. While currently unpatched CVEs are zero, the recurrence of XSS vulnerabilities indicates potential weaknesses in input sanitization, even if not flagged as critical in the current taint analysis. The lack of nonce checks on the unprotected AJAX handler, combined with the historical XSS issues, presents a notable risk. The plugin's overall security is bolstered by its proper handling of SQL and a decent output escaping rate, but the unprotected AJAX endpoint and past vulnerabilities necessitate caution.
Key Concerns
- AJAX handler without auth checks
- 0 Nonce checks
- 2 Medium severity CVEs historically
- 73% Output escaping
Anchor Episodes Index (Spotify for Podcasters) Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Anchor Episodes Index (Spotify for Podcasters) <= 2.1.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via anchor_episodes Shortcode
Anchor Episodes Index (Spotify for Podcasters) <= 2.1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting
Anchor Episodes Index (Spotify for Podcasters) Code Analysis
Output Escaping
Anchor Episodes Index (Spotify for Podcasters) Attack Surface
AJAX Handlers 1
Shortcodes 2
WordPress Hooks 9
Scheduled Events 1
Maintenance & Trust
Anchor Episodes Index (Spotify for Podcasters) Maintenance & Trust
Maintenance Signals
Community Trust
Anchor Episodes Index (Spotify for Podcasters) Alternatives
Share Interactive Content from Spotify – By PulseShare
pulseshare
Share interactive content from Spotify on your website seamlessly without any embed codes.
WP Podcasts Manager
wp-podcasts-manager
Short Description: Import and display podcast episodes from RSS feeds including Spotify support.
ETH Embed Anchor.fm
eth-embed-anchor-fm
Allow embedding Anchor.fm podcast episodes in your content.
PowerPress Podcasting plugin by Blubrry
powerpress
No. 1 Podcasting plugin for WordPress.
Podcast Subscribe Buttons
podcast-subscribe-buttons
Add beautiful podcast subscribe buttons anywhere.
Anchor Episodes Index (Spotify for Podcasters) Developer Profile
1 plugin · 1K total installs
How We Detect Anchor Episodes Index (Spotify for Podcasters)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/anchor-episodes-index/dist/main.css/wp-content/plugins/anchor-episodes-index/dist/jesaei.bundle.js/wp-content/plugins/anchor-episodes-index/dist/localized.js/wp-content/plugins/anchor-episodes-index/assets/admin.css/wp-content/plugins/anchor-episodes-index/dist/jesaei.bundle.js/wp-content/plugins/anchor-episodes-index/dist/localized.jsanchor-episodes-index/dist/main.css?ver=anchor-episodes-index/dist/jesaei.bundle.js?ver=anchor-episodes-index/dist/localized.js?ver=anchor-episodes-index/assets/admin.css?ver=HTML / DOM Fingerprints
jesaei-player-containerpro-active-yespro-active-nojesaeip-dark-themejesaei-player-loading-animationlds-ellipsisjesaei-anchor-podcast-iframe-containerjesaei-plugin-pro-linkid="jesaei-player-container"id="jesaei-player-loading-animation"id="jesaei-anchor-podcast-iframe-container"id="jesaei-anchor-podcast-iframe"name="jesaei_podcast_iframe"jesaei_settings<div id="jesaei-player-container"<div id="jesaei-player-loading-animation"<iframe id="jesaei-anchor-podcast-iframe"src="/embed"