
Lewe ChordPress – ChordPro Text Formatter Security & Risk Analysis
wordpress.org/plugins/chordpressLewe ChordPress for WordPress pretty-prints ChordPro formatted text and chord diagrams on your pages or posts.
Is Lewe ChordPress – ChordPro Text Formatter Safe to Use in 2026?
Mostly Safe
Score 78/100Lewe ChordPress – ChordPro Text Formatter is generally safe to use. 1 past CVE were resolved. Keep it updated.
The Chordpress v4.0.1 plugin presents a mixed security profile. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and performing capability checks on a significant portion of its operations. The absence of dangerous functions and file operations is also a strong indicator of a well-developed codebase. However, several areas raise concerns. A notable issue is the presence of one unsanitized path in the taint analysis, which, although not categorized as critical or high severity in this report, represents a potential vulnerability that could be exploited. Furthermore, the plugin has a history of known vulnerabilities, with one medium-severity CVE currently unpatched, indicating a potential for recurring security flaws or delayed patching. The plugin's last vulnerability was recorded on June 19, 2025, which is in the future, suggesting a potential data anomaly or forward-looking tracking. The output escaping, while extensive, has a significant percentage (26%) that is not properly escaped, posing a risk of XSS attacks. In conclusion, while Chordpress implements several security best practices, the unpatched CVE, taint analysis findings, and output escaping issues warrant careful consideration and prompt remediation.
Key Concerns
- Unpatched CVE present
- Unsanitized path in taint analysis
- Significant unescaped output detected
- Bundled library TinyMCE
Lewe ChordPress – ChordPro Text Formatter Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Lewe ChordPress <= 3.9.7 - Cross-Site Request Forgery to Stored Cross-Site Scripting
Lewe ChordPress – ChordPro Text Formatter Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Lewe ChordPress – ChordPro Text Formatter Attack Surface
Shortcodes 3
WordPress Hooks 21
Maintenance & Trust
Lewe ChordPress – ChordPro Text Formatter Maintenance & Trust
Maintenance Signals
Community Trust
Lewe ChordPress – ChordPro Text Formatter Alternatives
Chords and Lyrics
chords-and-lyrics
ChordsAndLyrics will format staffless lead sheets.
WP Chords
wp-chords
WP Chords allows you to format and display the chords on your blog including mobile friendly interface and AMP functionality.
Lyrics
lyrics-block
Add lyrics to your WordPress posts and pages.
ChordChartWP
chordchartwp
Users write shortcodes of text tab notation which will be then be parsed and rendered as svg chord chart images.
jTab Guitar Tab Shortcode
jtab-guitar-tab-shortcode
Displays guitar chords and tab into posts and pages using clean SVG vector graphics, based on the jTab JavaScript library by Paul Gallagher.
Lewe ChordPress – ChordPro Text Formatter Developer Profile
2 plugins · 210 total installs
How We Detect Lewe ChordPress – ChordPro Text Formatter
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/chordpress/admin/css/chordpress-admin.css/wp-content/plugins/chordpress/global/js/svguitar.umd.js/wp-content/plugins/chordpress/admin/js/chordpress-admin.jschordpress-admin.css?ver=chordpress-admin.js?ver=HTML / DOM Fingerprints
chordpress-admin-pagedata-chordpress-actiondata-chordpress-modaldata-chordpress-titlewindow.chordpress_admin_ajax_object