Colbass – a Read-Aloud player (Text to Speech) AI audio player Security & Risk Analysis

wordpress.org/plugins/colbass-read-aloud-player

Enjoy the first month free! No commitment required, cancel anytime. A read-aloud player will be added to every article.

0 active installs v1.3.18 PHP 7.2+ WP 5.2+ Updated Aug 5, 2025
accessibilityaudio-playerread-aloudtext-to-audiotext-to-speech
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Colbass – a Read-Aloud player (Text to Speech) AI audio player Safe to Use in 2026?

Generally Safe

Score 100/100

Colbass – a Read-Aloud player (Text to Speech) AI audio player has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9mo ago
Risk Assessment

The colbass-read-aloud-player plugin version 1.3.18 exhibits a generally positive security posture, with strong adherence to secure coding practices. The absence of known CVEs, critical or high-severity taint flows, raw SQL queries, and file operations are commendable. The high percentage of properly escaped output and the use of prepared statements for any SQL queries (even though none were found in the static analysis) suggest a developer focused on security. The plugin also implements nonce checks and capability checks on some of its entry points, which is a good practice.

However, there are notable security concerns. The plugin exposes two AJAX handlers without any authentication or capability checks. This creates a significant attack surface, as unauthenticated users could potentially interact with these endpoints and trigger unintended actions. While the static analysis didn't reveal specific exploitable vulnerabilities in these handlers, their unprotected nature is a considerable risk. The plugin also makes external HTTP requests, which could be a vector for vulnerabilities if not handled carefully, although no specific issues were flagged in the static analysis.

In conclusion, the plugin has strengths in its code quality regarding SQL and output escaping and a clean vulnerability history. Nevertheless, the two unprotected AJAX endpoints represent a substantial weakness that should be addressed to mitigate potential security risks and improve the overall security posture of the plugin.

Key Concerns

  • AJAX handlers without auth checks
  • Two AJAX handlers without auth checks
Vulnerabilities
None known

Colbass – a Read-Aloud player (Text to Speech) AI audio player Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Colbass – a Read-Aloud player (Text to Speech) AI audio player Release Timeline

v1.3.11
v1.3.10
v1.3.9
v1.3.8
v1.3.7
v1.3.6
v1.3.5
v1.3.4
v1.3.3
v1.3.2
v1.3.1
v1.3.0
Code Analysis
Analyzed Apr 16, 2026

Colbass – a Read-Aloud player (Text to Speech) AI audio player Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
62 escaped
Nonce Checks
2
Capability Checks
1
File Operations
0
External Requests
3
Bundled Libraries
0

Output Escaping

98% escaped63 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

3 flows
my_audio_player_settings_page (colbass.php:173)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Colbass – a Read-Aloud player (Text to Speech) AI audio player Attack Surface

Entry Points3
Unprotected2

AJAX Handlers 2

authwp_ajax_get_source_voices_gcolbass.php:548
noprivwp_ajax_get_source_voices_gcolbass.php:549

Shortcodes 1

[colbass_tts_wrap] colbass.php:692
WordPress Hooks 7
actionadmin_enqueue_scriptscolbass.php:55
actionadmin_menucolbass.php:64
filterthe_contentcolbass.php:99
actionadmin_post_save_my_plugin_settingscolbass.php:434
actionpost_updatedcolbass.php:625
filterscript_loader_tagcolbass.php:641
actionwp_enqueue_scriptscolbass.php:656
Maintenance & Trust

Colbass – a Read-Aloud player (Text to Speech) AI audio player Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedAug 5, 2025
PHP min version7.2
Downloads2K

Community Trust

Rating100/100
Number of ratings2
Active installs0
Developer Profile

Colbass – a Read-Aloud player (Text to Speech) AI audio player Developer Profile

colbass

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Colbass – a Read-Aloud player (Text to Speech) AI audio player

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/colbass-read-aloud-player/assets/css/style.css
Version Parameters
colbass-read-aloud-player/assets/css/style.css?ver=

HTML / DOM Fingerprints

CSS Classes
cb_wrap
Data Attributes
id="colbass-tts-wrap"support="https://colbass.com"selectorcolorselectorBodyselectorBriefselectorTitle+2 more
JS Globals
window.playText
REST Endpoints
/wp-json/colbass-read-aloud-player/v1/get-post-data
Shortcode Output
<div id="colbass-tts-wrap"
FAQ

Frequently Asked Questions about Colbass – a Read-Aloud player (Text to Speech) AI audio player