
Codescar Radio Widget Security & Risk Analysis
wordpress.org/plugins/codescar-radio-widgetCodescar Radio Widget produces a widget allowing users listen to a radio station from your website.
Is Codescar Radio Widget Safe to Use in 2026?
Use With Caution
Score 63/100Codescar Radio Widget has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "codescar-radio-widget" plugin exhibits a mixed security posture. While the static analysis indicates a small attack surface with no directly exposed entry points and SQL queries utilizing prepared statements, there are significant concerns regarding output escaping. The fact that 0% of the 33 outputs are properly escaped presents a high risk of Cross-Site Scripting (XSS) vulnerabilities, allowing malicious code to be injected into pages where the widget is displayed.
The vulnerability history further exacerbates these concerns. The presence of a known, unpatched medium-severity CVE, specifically identified as Cross-Site Request Forgery (CSRF), indicates a historical weakness in the plugin's security. The fact that this vulnerability was recently discovered (2025-04-09) and remains unpatched is a critical red flag. While the static analysis did not detect any taint flows or critical vulnerabilities, the historical pattern and the significant output escaping issues strongly suggest that this plugin should be approached with caution.
In conclusion, despite a seemingly small attack surface and good practices in database interaction, the plugin's severe deficiency in output escaping and its unpatched CSRF vulnerability present significant risks. Users should be aware that the lack of proper output sanitization makes XSS attacks highly probable, and the unpatched CSRF vulnerability leaves the door open for unauthorized actions. The plugin's strengths in SQL security are overshadowed by these critical weaknesses.
Key Concerns
- Unpatched CVE (medium severity)
- All outputs unescaped
- Missing capability checks on entry points (all 0)
- Missing nonce checks on AJAX handlers (all 0)
Codescar Radio Widget Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Codescar Radio Widget <= 0.4.2 - Cross-Site Request Forgery to Stored Cross-Site Scripting
Codescar Radio Widget Code Analysis
Output Escaping
Codescar Radio Widget Attack Surface
WordPress Hooks 4
Maintenance & Trust
Codescar Radio Widget Maintenance & Trust
Maintenance Signals
Community Trust
Codescar Radio Widget Alternatives
Radio Station by netmix® – Manage and play your Show Schedule in WordPress!
radio-station
Radio Station lets you build and manage a Show Schedule for a radio station or Internet broadcaster's WordPress website.
Shoutcast Icecast HTML5 Radio Player
shoutcast-icecast-html5-radio-player
A secure HTML5 radio player for Shoutcast, Icecast, and podcast streams with social sharing.
StreamCast – Live Radio Streaming Player
streamcast
StreamCast allows you to play IceCast, Shoutcast, Radionomy, RadioJar, RadioCo and more beautifully inside WordPress.
Radio Player Page
radio-player-page
Dedicated player pages for your radio streams, with program scheduling and continuous playback.
Serverless Radio
serverless-radio
A serverless MP3 linear streaming plugin that lets you create AutoDJ-like playlists from public MP3 folders — no VPS required.
Codescar Radio Widget Developer Profile
1 plugin · 90 total installs
How We Detect Codescar Radio Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/codescar-radio-widget/radio-widget-settings.phpcodescar-radio-widget/radio-widget-settings.php?ver=HTML / DOM Fingerprints
radio-widgetradio_blockradio_controlsradio_cubeid="radio_player"id="radio_controls"id="radio_play"id="radio_mute"id="radio_volume"id="radio_stations"