
F13 Last.fm album Shortcode Security & Risk Analysis
wordpress.org/plugins/f13-lastfm-album-shortcodeAdd information to you blog about a musical album using shortcode.
Is F13 Last.fm album Shortcode Safe to Use in 2026?
Generally Safe
Score 85/100F13 Last.fm album Shortcode has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The f13-lastfm-album-shortcode plugin version 1.0 exhibits a generally strong security posture based on the provided static analysis. It avoids dangerous functions, uses prepared statements for all SQL queries, and properly escapes all output. There are no observed file operations or external HTTP requests that appear to be insecurely handled. The lack of critical or high-severity taint flows further indicates a well-written codebase in terms of sanitization.
However, there are notable areas for concern. The absence of any nonce checks or capability checks across all identified entry points is a significant weakness. While the current attack surface is small and appears to be protected by default WordPress authentication mechanisms, the lack of explicit checks leaves it vulnerable to potential CSRF attacks or unauthorized access if WordPress's internal protections were bypassed or misconfigured. The vulnerability history being clean is positive, but it doesn't negate the risks introduced by the current code's security practices.
In conclusion, the plugin demonstrates good coding practices regarding data handling and output sanitization. Nevertheless, the complete lack of explicit nonce and capability checks represents a critical oversight that could lead to vulnerabilities. A future update should prioritize implementing these essential security measures to harden the plugin against common web attacks.
Key Concerns
- Missing nonce checks on entry points
- Missing capability checks on entry points
F13 Last.fm album Shortcode Security Vulnerabilities
F13 Last.fm album Shortcode Code Analysis
SQL Query Safety
Output Escaping
F13 Last.fm album Shortcode Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
F13 Last.fm album Shortcode Maintenance & Trust
Maintenance Signals
Community Trust
F13 Last.fm album Shortcode Alternatives
User Shortcodes
user-shortcodes
Add a simple list of shortcodes to WordPress in order to display the current user information.
A1 Tools
a1-tools
Centrally manage contact information, social media links, and business details across your WordPress sites from the A1 Tools platform.
Last.fm for WordPress
lastfm-for-wordpress
Last.fm for WordPress displays your recently listened tracks in your WordPress blog.
Gleam Shortcodes
gleam-shortcodes
Add a simple list of shortcodes to WordPress in order to display the current user information.
Last.fm RPS
lastfm-rps
Widget Plugin that lists your recently listened songs on your sidebar with album or artist images and text.
F13 Last.fm album Shortcode Developer Profile
8 plugins · 90 total installs
How We Detect F13 Last.fm album Shortcode
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/f13-lastfm-album-shortcode/f13-lastfm-album-shortcode.phpHTML / DOM Fingerprints
name="lfmastoken"name="lfmascache_timeout"[album artist="" album=""]