
Player for SoundCloud – Embed and Play Audio Tracks Security & Risk Analysis
wordpress.org/plugins/embed-soundcloud-blockSoundCloud is the new music network on the block that allows users to create, record and share sounds and music with family, friends and the world.
Is Player for SoundCloud – Embed and Play Audio Tracks Safe to Use in 2026?
Generally Safe
Score 100/100Player for SoundCloud – Embed and Play Audio Tracks has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The embed-soundcloud-block plugin exhibits a generally strong security posture based on the provided static analysis. The plugin demonstrates good practices by utilizing prepared statements for all SQL queries and having a high percentage of properly escaped output. The lack of any recorded vulnerabilities, critical taint flows, or dangerous functions further reinforces this positive assessment. The presence of nonce and capability checks on entry points indicates an effort to protect against common web attacks.
However, there are a few areas that warrant attention. The plugin's attack surface, while small, includes an AJAX handler that lacks an explicit authentication check, presenting a potential, albeit low-probability, risk if exploited. While no unsanitized paths were found in the taint analysis, the plugin does make an external HTTP request, which could be a vector for certain types of attacks if not handled with extreme care. The bundling of Freemius, while common, can sometimes introduce maintenance challenges if not kept up-to-date.
Overall, the plugin appears to be well-developed from a security perspective, with a clean vulnerability history and robust coding practices in key areas. The identified minor concerns should be reviewed, but they do not currently indicate a high-risk plugin. Continued vigilance in maintaining the plugin and addressing any potential security implications of external dependencies will be important.
Key Concerns
- AJAX handler without auth check
- External HTTP request present
- Bundled Freemius library
Player for SoundCloud – Embed and Play Audio Tracks Security Vulnerabilities
Player for SoundCloud – Embed and Play Audio Tracks Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Player for SoundCloud – Embed and Play Audio Tracks Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 16
Maintenance & Trust
Player for SoundCloud – Embed and Play Audio Tracks Maintenance & Trust
Maintenance Signals
Community Trust
Player for SoundCloud – Embed and Play Audio Tracks Alternatives
Music Player for Elementor – Audio Player & Podcast Player
music-player-for-elementor
Audio Player for Elementor – the go-to plugin for adding MP3s, podcasts & playlists. Fully customizable, WooCommerce-ready, and mobile-friendly.
Audio Player Block – Advanced Block for Embedding Audio Files
audio-player-block
A block for embedding a beautiful audio player.
HTML5 jQuery Audio Player
html5-jquery-audio-player
Finally, a trendy looking audio player plugin. Works on all modern browsers including iPhone/iPad.
Radiojar Audio Player
radiojar-player
Audio player plugin for Radiojar platform , just by dragging the widget or added shortcode [rj-player].
iSimpleDesign Amazon S3 Music Player Plugin
isimpledesign-amazon-s3-music-player-plugin
I created this simple plugin to allow wordpress users to stream music from their amazon s3 storage account.
Player for SoundCloud – Embed and Play Audio Tracks Developer Profile
120 plugins · 738K total installs
How We Detect Player for SoundCloud – Embed and Play Audio Tracks
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/embed-soundcloud-block/assets/css/admin.css/wp-content/plugins/embed-soundcloud-block/assets/js/admin.js/wp-content/plugins/embed-soundcloud-block/assets/js/soundCloud.api.js/wp-content/plugins/embed-soundcloud-block/freemius-lite/start.phpembed-soundcloud-block/assets/css/admin.css?ver=embed-soundcloud-block/assets/js/admin.js?ver=embed-soundcloud-block/assets/js/soundCloud.api.js?ver=HTML / DOM Fingerprints
scb_block_wrapperdata-block-idSCB_ASSETS_DIRSCB_PLUGIN_VERSIONSCB_PLUGIN_PATHSCB_DIR_URL/wp-json/bplugins/v1/get_content