Player for SoundCloud – Embed and Play Audio Tracks Security & Risk Analysis

wordpress.org/plugins/embed-soundcloud-block

SoundCloud is the new music network on the block that allows users to create, record and share sounds and music with family, friends and the world.

1K active installs v1.0.11 PHP 7.1+ WP 6.5+ Updated Feb 26, 2026
blockgutenberg-soundcloudmp3-playermusic-playersoundcloud
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Player for SoundCloud – Embed and Play Audio Tracks Safe to Use in 2026?

Generally Safe

Score 100/100

Player for SoundCloud – Embed and Play Audio Tracks has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The embed-soundcloud-block plugin exhibits a generally strong security posture based on the provided static analysis. The plugin demonstrates good practices by utilizing prepared statements for all SQL queries and having a high percentage of properly escaped output. The lack of any recorded vulnerabilities, critical taint flows, or dangerous functions further reinforces this positive assessment. The presence of nonce and capability checks on entry points indicates an effort to protect against common web attacks.

However, there are a few areas that warrant attention. The plugin's attack surface, while small, includes an AJAX handler that lacks an explicit authentication check, presenting a potential, albeit low-probability, risk if exploited. While no unsanitized paths were found in the taint analysis, the plugin does make an external HTTP request, which could be a vector for certain types of attacks if not handled with extreme care. The bundling of Freemius, while common, can sometimes introduce maintenance challenges if not kept up-to-date.

Overall, the plugin appears to be well-developed from a security perspective, with a clean vulnerability history and robust coding practices in key areas. The identified minor concerns should be reviewed, but they do not currently indicate a high-risk plugin. Continued vigilance in maintaining the plugin and addressing any potential security implications of external dependencies will be important.

Key Concerns

  • AJAX handler without auth check
  • External HTTP request present
  • Bundled Freemius library
Vulnerabilities
None known

Player for SoundCloud – Embed and Play Audio Tracks Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Player for SoundCloud – Embed and Play Audio Tracks Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
38 escaped
Nonce Checks
3
Capability Checks
5
File Operations
0
External Requests
1
Bundled Libraries
1

Bundled Libraries

Freemius

Output Escaping

97% escaped39 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
fs_init (freemius-lite\inc\Base\FSActivate.php:68)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Player for SoundCloud – Embed and Play Audio Tracks Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 1

authwp_ajax_fs_initfreemius-lite\inc\Base\FSActivate.php:42

Shortcodes 1

[scb-sound-cloud] includes\post-type\shortcode.php:9
WordPress Hooks 16
actionadmin_headfreemius-lite\inc\Base\FSActivate.php:29
actionadmin_enqueue_scriptsfreemius-lite\inc\Base\FSActivate.php:30
actionadmin_menufreemius-lite\inc\Base\FSActivate.php:33
actionadmin_footerfreemius-lite\inc\Base\FSActivate.php:38
actionadmin_footerfreemius-lite\inc\Base\FSActivate.php:39
actionadmin_noticesfreemius-lite\inc\Base\FSActivate.php:44
actioninitfreemius-lite\inc\Base\FS_Lite.php:29
actionadmin_enqueue_scriptsincludes\admin-menu.php:7
actionadmin_menuincludes\admin-menu.php:8
actioninitincludes\post-type\shortcode.php:8
filtermanage_scb_sound_cloud_posts_columnsincludes\post-type\shortcode.php:10
actionmanage_scb_sound_cloud_posts_custom_columnincludes\post-type\shortcode.php:11
actionuse_block_editor_for_postincludes\post-type\shortcode.php:12
actionenqueue_block_assetsindex.php:77
actioninitindex.php:78
actionadmin_enqueue_scriptsindex.php:79
Maintenance & Trust

Player for SoundCloud – Embed and Play Audio Tracks Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 26, 2026
PHP min version7.1
Downloads21K

Community Trust

Rating100/100
Number of ratings1
Active installs1K
Developer Profile

Player for SoundCloud – Embed and Play Audio Tracks Developer Profile

colorlibplugins

120 plugins · 738K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
140 days
View full developer profile
Detection Fingerprints

How We Detect Player for SoundCloud – Embed and Play Audio Tracks

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/embed-soundcloud-block/assets/css/admin.css/wp-content/plugins/embed-soundcloud-block/assets/js/admin.js/wp-content/plugins/embed-soundcloud-block/assets/js/soundCloud.api.js
Script Paths
/wp-content/plugins/embed-soundcloud-block/freemius-lite/start.php
Version Parameters
embed-soundcloud-block/assets/css/admin.css?ver=embed-soundcloud-block/assets/js/admin.js?ver=embed-soundcloud-block/assets/js/soundCloud.api.js?ver=

HTML / DOM Fingerprints

CSS Classes
scb_block_wrapper
Data Attributes
data-block-id
JS Globals
SCB_ASSETS_DIRSCB_PLUGIN_VERSIONSCB_PLUGIN_PATHSCB_DIR_URL
REST Endpoints
/wp-json/bplugins/v1/get_content
FAQ

Frequently Asked Questions about Player for SoundCloud – Embed and Play Audio Tracks