Compact WP Audio Player Security & Risk Analysis

wordpress.org/plugins/compact-wp-audio-player

A Compact WP Audio Player Plugin that is compatible with all major browsers and devices (Android, iPhone, iPad)

20K active installs v1.9.15 PHP + WP 5.0+ Updated Dec 2, 2025
audioaudio-playerembedmediamedia-player
97
A · Safe
CVEs total6
Unpatched0
Last CVEJan 3, 2025
Safety Verdict

Is Compact WP Audio Player Safe to Use in 2026?

Generally Safe

Score 97/100

Compact WP Audio Player has a strong security track record. Known vulnerabilities have been patched promptly.

6 known CVEsLast CVE: Jan 3, 2025Updated 4mo ago
Risk Assessment

The 'compact-wp-audio-player' plugin v1.9.15 presents a mixed security posture. Static analysis reveals a generally good implementation of secure coding practices, with 100% of SQL queries using prepared statements and a high percentage of output being properly escaped. The limited attack surface of two shortcodes, with no apparent direct vulnerabilities found in the static analysis for AJAX or REST API, is also a positive sign. However, the plugin's vulnerability history is a significant concern. With a total of 6 known CVEs, all categorized as medium severity and primarily involving SSRF, CSRF, and XSS, this indicates a recurring pattern of exploitable weaknesses. The fact that these are all currently unpatched, despite the latest vulnerability being dated in the future (2025-01-03), is highly problematic and suggests a lack of ongoing maintenance or a potential data anomaly regarding the patch status.

Key Concerns

  • Significant vulnerability history (6 CVEs)
  • Vulnerabilities of common types (SSRF, CSRF, XSS)
  • All known CVEs currently unpatched
  • External HTTP requests detected
  • Capability checks missing
Vulnerabilities
6

Compact WP Audio Player Security Vulnerabilities

CVEs by Year

2 CVEs in 2021
2021
1 CVE in 2022
2022
2 CVEs in 2024
2024
1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
6

6 total CVEs

CVE-2024-56279medium · 6.4Server-Side Request Forgery (SSRF)

Compact WP Audio Player <= 1.9.14 - Authenticated (Contributor+) Server-Side Request Forgery

Jan 3, 2025 Patched in 1.9.15 (6d)
CVE-2024-10176medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Compact WP Audio Player <= 1.9.13 - Authenticated (Contributor+) Stored Cross-Site Scripting via sc_embed_player Shortcode

Oct 23, 2024 Patched in 1.9.14 (1d)
CVE-2024-29917medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Compact WP Audio Player <= 1.9.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via fileurl

Mar 25, 2024 Patched in 1.9.10 (5d)
CVE-2022-4542medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Compact WP Audio Player <= 1.9.7 - Authenticated (Contributor+) Stored Cross-Site Scripting

Dec 27, 2022 Patched in 1.9.8 (392d)
CVE-2021-24735medium · 4.3Cross-Site Request Forgery (CSRF)

Compact WP Audio Player <= 1.9.6 - Setting Change via Cross-Site Request Forgery

Sep 15, 2021 Patched in 1.9.7 (860d)
CVE-2021-24734medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Compact WP Audio Player <= 1.9.6 - Contributor+ Stored Cross-Site Scripting

Sep 15, 2021 Patched in 1.9.7 (860d)
Code Analysis
Analyzed Mar 16, 2026

Compact WP Audio Player Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
30 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

94% escaped32 total outputs
Attack Surface

Compact WP Audio Player Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[sc_embed_player] shortcodes-functions.php:3
[sc_embed_player_template1] shortcodes-functions.php:4
WordPress Hooks 6
actioninitsc_audio_player.php:21
filterplugin_action_linkssc_audio_player.php:42
actionwp_footersc_audio_player.php:128
actionadmin_menusc_audio_player.php:131
filterwidget_textshortcodes-functions.php:7
filterthe_excerptshortcodes-functions.php:9
Maintenance & Trust

Compact WP Audio Player Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 2, 2025
PHP min version
Downloads662K

Community Trust

Rating82/100
Number of ratings68
Active installs20K
Developer Profile

Compact WP Audio Player Developer Profile

mra13

15 plugins · 210K total installs

76
trust score
Avg Security Score
95/100
Avg Patch Time
629 days
View full developer profile
Detection Fingerprints

How We Detect Compact WP Audio Player

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/compact-wp-audio-player/css/flashblock.css/wp-content/plugins/compact-wp-audio-player/css/player.css/wp-content/plugins/compact-wp-audio-player/js/soundmanager2-nodebug-jsmin.js
Script Paths
/wp-content/plugins/compact-wp-audio-player/js/soundmanager2-nodebug-jsmin.js
Version Parameters
compact-wp-audio-player/style.css?ver=compact-wp-audio-player/script.js?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- WP Audio player plugin v1.9.15 - https://www.tipsandtricks-hq.com/wordpress-audio-music-player-plugin-4556/ -->
Data Attributes
id="btnplay_"id="btnstop_"
JS Globals
soundManagerplay_mp3show_hideloopSoundstop_all_tracks
Shortcode Output
[sc_embed_player fileurl=
FAQ

Frequently Asked Questions about Compact WP Audio Player