Anchor Episodes Index (Spotify for Podcasters) Security & Risk Analysis

wordpress.org/plugins/anchor-episodes-index

A lightweight plugin that allows you to output an anchor.fm podcast player on your site that includes an episode index. Just add two URL's on the …

1K active installs v2.1.15 PHP 7.4+ WP 4.8+ Updated Dec 7, 2025
anchor-fmembedpodcastspotify
99
A · Safe
CVEs total2
Unpatched0
Last CVEOct 21, 2024
Download
Safety Verdict

Is Anchor Episodes Index (Spotify for Podcasters) Safe to Use in 2026?

Generally Safe

Score 99/100

Anchor Episodes Index (Spotify for Podcasters) has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Oct 21, 2024Updated 3mo ago
Risk Assessment

The "anchor-episodes-index" plugin v2.1.15 exhibits a mixed security posture. On the positive side, it demonstrates good practices with SQL queries exclusively using prepared statements and a reasonable percentage of output escaping. The absence of dangerous functions and critical or high-severity taint flows suggests a level of care in its development. However, significant concerns arise from the static analysis, particularly the presence of an AJAX handler without authentication checks. This creates a direct entry point for potential attackers. The vulnerability history is also a concern, with two known medium-severity CVEs, both related to Cross-Site Scripting. While currently unpatched CVEs are zero, the recurrence of XSS vulnerabilities indicates potential weaknesses in input sanitization, even if not flagged as critical in the current taint analysis. The lack of nonce checks on the unprotected AJAX handler, combined with the historical XSS issues, presents a notable risk. The plugin's overall security is bolstered by its proper handling of SQL and a decent output escaping rate, but the unprotected AJAX endpoint and past vulnerabilities necessitate caution.

Key Concerns

  • AJAX handler without auth checks
  • 0 Nonce checks
  • 2 Medium severity CVEs historically
  • 73% Output escaping
Vulnerabilities
2

Anchor Episodes Index (Spotify for Podcasters) Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2024-10189medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Anchor Episodes Index (Spotify for Podcasters) <= 2.1.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via anchor_episodes Shortcode

Oct 21, 2024 Patched in 2.1.11 (1d)
CVE-2023-44145medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Anchor Episodes Index (Spotify for Podcasters) <= 2.1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting

Sep 20, 2023 Patched in 2.1.8 (125d)
Code Analysis
Analyzed Mar 16, 2026

Anchor Episodes Index (Spotify for Podcasters) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
19 escaped
Nonce Checks
0
Capability Checks
1
File Operations
3
External Requests
1
Bundled Libraries
0

Output Escaping

73% escaped26 total outputs
Attack Surface
1 unprotected

Anchor Episodes Index (Spotify for Podcasters) Attack Surface

Entry Points3
Unprotected1

AJAX Handlers 1

authwp_ajax_jesaei_dismiss_noticeincludes\main.php:29

Shortcodes 2

[anchor_episodes] includes\main.php:22
[anchor_episodes] includes\main.php:43
WordPress Hooks 9
actionjesaei_hourly_eventanchor-episodes-index.php:43
actionadmin_menuincludes\admin-settings-page.php:10
actionadmin_initincludes\admin-settings-page.php:11
actionwp_enqueue_scriptsincludes\main.php:19
actionadmin_enqueue_scriptsincludes\main.php:21
actioninitincludes\main.php:23
actionupdated_optionincludes\main.php:26
actionupgrader_post_installincludes\main.php:27
actionadmin_noticesincludes\main.php:28

Scheduled Events 1

jesaei_hourly_event
Maintenance & Trust

Anchor Episodes Index (Spotify for Podcasters) Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 7, 2025
PHP min version7.4
Downloads46K

Community Trust

Rating96/100
Number of ratings5
Active installs1K
Developer Profile

Anchor Episodes Index (Spotify for Podcasters) Developer Profile

Jesse Sugden

1 plugin · 1K total installs

87
trust score
Avg Security Score
99/100
Avg Patch Time
63 days
View full developer profile
Detection Fingerprints

How We Detect Anchor Episodes Index (Spotify for Podcasters)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/anchor-episodes-index/dist/main.css/wp-content/plugins/anchor-episodes-index/dist/jesaei.bundle.js/wp-content/plugins/anchor-episodes-index/dist/localized.js/wp-content/plugins/anchor-episodes-index/assets/admin.css
Script Paths
/wp-content/plugins/anchor-episodes-index/dist/jesaei.bundle.js/wp-content/plugins/anchor-episodes-index/dist/localized.js
Version Parameters
anchor-episodes-index/dist/main.css?ver=anchor-episodes-index/dist/jesaei.bundle.js?ver=anchor-episodes-index/dist/localized.js?ver=anchor-episodes-index/assets/admin.css?ver=

HTML / DOM Fingerprints

CSS Classes
jesaei-player-containerpro-active-yespro-active-nojesaeip-dark-themejesaei-player-loading-animationlds-ellipsisjesaei-anchor-podcast-iframe-containerjesaei-plugin-pro-link
Data Attributes
id="jesaei-player-container"id="jesaei-player-loading-animation"id="jesaei-anchor-podcast-iframe-container"id="jesaei-anchor-podcast-iframe"name="jesaei_podcast_iframe"
JS Globals
jesaei_settings
Shortcode Output
<div id="jesaei-player-container"<div id="jesaei-player-loading-animation"<iframe id="jesaei-anchor-podcast-iframe"src="/embed"
FAQ

Frequently Asked Questions about Anchor Episodes Index (Spotify for Podcasters)