Audio Comparison Lite Security & Risk Analysis

wordpress.org/plugins/audio-comparison-lite

Time synchronized A/B comparison for audio files (mp3, wav...).

30 active installs v3.9 PHP 7.0+ WP 4.0+ Updated Sep 30, 2025
ab-testingaudiocomparisonmasteringmixing
99
A · Safe
CVEs total1
Unpatched0
Last CVEOct 31, 2024
Safety Verdict

Is Audio Comparison Lite Safe to Use in 2026?

Generally Safe

Score 99/100

Audio Comparison Lite has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Oct 31, 2024Updated 7mo ago
Risk Assessment

The 'audio-comparison-lite' v3.9 plugin exhibits a generally strong security posture based on the provided static analysis. The complete absence of dangerous functions, raw SQL queries, unescaped output, file operations, and a low number of external HTTP requests are all positive indicators. The presence of a nonce check is also a good sign, though the lack of capability checks on any identified entry points (which are zero in this analysis) is a point of note. The taint analysis revealing two flows with unsanitized paths, while not classified as critical or high, warrants attention as it suggests potential areas where user input might not be fully sanitized before use.

The vulnerability history shows one past medium vulnerability related to Cross-site Scripting. While this vulnerability is marked as currently unpatched, the fact that it's a single, medium-severity issue from over six months ago, and the plugin's current analysis shows good practices, suggests that the developers may have addressed this in subsequent versions or that the specific condition for exploitation is rare. Overall, the plugin demonstrates good fundamental security practices, but the identified taint flows and the historical vulnerability indicate that ongoing vigilance and potential code review for the identified taint paths would be prudent.

Key Concerns

  • Flows with unsanitized paths
  • Historical medium vulnerability
  • No capability checks on entry points
Vulnerabilities
1 published

Audio Comparison Lite Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-51627medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Audio Comparison Lite <= 3.4 - Authenticated (Contributor+) Stored Cross-Site Scripting

Oct 31, 2024 Patched in 3.5 (12d)
Version History

Audio Comparison Lite Release Timeline

v3.9Current
v3.8
v3.7
v3.6
v3.5
v3.41 CVE
v3.31 CVE
v3.11 CVE
v3.01 CVE
v2.81 CVE
v2.71 CVE
v2.61 CVE
v2.41 CVE
v2.31 CVE
v2.21 CVE
v2.11 CVE
v2.01 CVE
v1.111 CVE
v1.101 CVE
v1.91 CVE
Code Analysis
Analyzed Apr 16, 2026

Audio Comparison Lite Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
46 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

100% escaped46 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
settings_page (audio-comparison.php:230)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Audio Comparison Lite Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionwp_enqueue_scriptsaudio-comparison.php:37
actioninitaudio-comparison.php:38
actionadmin_menuaudio-comparison.php:39
actionadmin_initaudio-comparison.php:40
filterplugin_action_linksaudio-comparison.php:188
filterplugin_row_metaaudio-comparison.php:189
actionadmin_noticesaudio-comparison.php:706
Maintenance & Trust

Audio Comparison Lite Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 30, 2025
PHP min version7.0
Downloads3K

Community Trust

Rating100/100
Number of ratings7
Active installs30
Developer Profile

Audio Comparison Lite Developer Profile

kaedinger

1 plugin · 30 total installs

93
trust score
Avg Security Score
99/100
Avg Patch Time
12 days
View full developer profile
Detection Fingerprints

How We Detect Audio Comparison Lite

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/audio-comparison-lite/audio-comparison.js
Script Paths
/wp-content/plugins/audio-comparison-lite/lib/howler.core.min.js/wp-content/plugins/audio-comparison-lite/audio-comparison.js
Version Parameters
audio-comparison-lite/audio-comparison.js?ver=

HTML / DOM Fingerprints

CSS Classes
audio-comparison-lite-play-stopaudio-comparison-lite-labelaudio-comparison-lite-play-aaudio-comparison-lite-play-b
HTML Comments
Audio Comparison Lite | https://audiocomparison.kaedinger.de/lite^^^ Audio Comparison Lite | https://audiocomparison.kaedinger.de/lite
Data Attributes
data-play-defaultdata-button-play-textdata-button-stop-textdata-playing-a-textdata-playing-b-textdata-buffering-text+3 more
JS Globals
howler-js
Shortcode Output
<div class="audio-comparison-lite"<button class="audio-comparison-lite-play-stop"><button class="audio-comparison-lite-play-a"><button class="audio-comparison-lite-play-b">
FAQ

Frequently Asked Questions about Audio Comparison Lite