DC Artists Security & Risk Analysis

wordpress.org/plugins/dc-artists

DC Artists is a simple plugin for creating a performing artist discography website.

10 active installs v1.4.0 PHP + WP 3.2+ Updated Jan 31, 2017
artistbandbuy-musiclabelmusic-manager
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is DC Artists Safe to Use in 2026?

Generally Safe

Score 85/100

DC Artists has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The dc-artists v1.4.0 plugin demonstrates a generally positive security posture with several good practices in place. The absence of known CVEs and a clean vulnerability history suggest a well-maintained plugin. Static analysis shows that all identified entry points (AJAX handlers) are protected by nonce checks, which is a significant strength. Furthermore, the plugin utilizes prepared statements for all SQL queries, mitigating the risk of SQL injection. However, there are areas for improvement. The taint analysis indicates one flow with unsanitized paths, which, while not currently flagged as critical or high severity, warrants attention as it represents a potential avenue for exploitation if data within that flow originates from user input. Additionally, only 60% of output operations are properly escaped, leaving a portion susceptible to cross-site scripting (XSS) vulnerabilities. The lack of capability checks on AJAX handlers, while mitigated by nonce checks, still represents a missed opportunity for robust access control.

Key Concerns

  • Flows with unsanitized paths
  • Unescaped output (40% of outputs)
  • Missing capability checks on AJAX
Vulnerabilities
None known

DC Artists Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

DC Artists Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
3 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

60% escaped5 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

3 flows1 with unsanitized paths
dca_souncloud_load (dcartists.php:99)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

DC Artists Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_dca_process_requestdcartists.php:21
noprivwp_ajax_dca_process_requestdcartists.php:22
WordPress Hooks 5
actioninitdcartists.php:18
actioninitdcartists.php:19
actioninitdcartists.php:20
actioninitdcartists.php:36
filterimage_size_names_choosedcartists.php:59
Maintenance & Trust

DC Artists Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.32
Last updatedJan 31, 2017
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

DC Artists Developer Profile

ganddser

3 plugins · 540 total installs

71
trust score
Avg Security Score
88/100
Avg Patch Time
673 days
View full developer profile
Detection Fingerprints

How We Detect DC Artists

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/dc-artists/css/main.css/wp-content/plugins/dc-artists/css/slideshow.css/wp-content/plugins/dc-artists/js/jquery.colorbox.js/wp-content/plugins/dc-artists/js/photo-script.js/wp-content/plugins/dc-artists/js/uploader.js/wp-content/plugins/dc-artists/js/uploader34.js/wp-content/plugins/dc-artists/js/media.js/wp-content/plugins/dc-artists/js/dca_votes.js+2 more
Script Paths
/wp-content/plugins/dc-artists/js/jquery.colorbox.js/wp-content/plugins/dc-artists/js/photo-script.js/wp-content/plugins/dc-artists/js/uploader.js/wp-content/plugins/dc-artists/js/uploader34.js/wp-content/plugins/dc-artists/js/media.js/wp-content/plugins/dc-artists/js/dca_votes.js+1 more
Version Parameters
dc-artists/css/main.css?ver=dc-artists/css/slideshow.css?ver=dc-artists/js/uploader.js?ver=dc-artists/js/uploader34.js?ver=dc-artists/js/media.js?ver=dc-artists/js/dca_votes.js?ver=dc-artists/js/dca_admin.js?ver=

HTML / DOM Fingerprints

JS Globals
myAjaxmyUpload
FAQ

Frequently Asked Questions about DC Artists