FnF.FM Bangla Radio Security & Risk Analysis

wordpress.org/plugins/fnffm-bangla-radio

FnF.FM Bangla Radio is an Online Radio Station that can be used as either a widget or Short code.

10 active installs v1.0 PHP + WP 3.0+ Updated Aug 25, 2016
banglapluginsradiosidebarwidget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is FnF.FM Bangla Radio Safe to Use in 2026?

Generally Safe

Score 85/100

FnF.FM Bangla Radio has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The "fnffm-bangla-radio" plugin version 1.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for SQL queries and has no known past vulnerabilities, suggesting a generally cautious development approach. The attack surface is also minimal with only one entry point (a shortcode) and no identified cron events or external HTTP requests. However, significant security concerns arise from the static analysis. The use of the `create_function` is a critical red flag, as it can be exploited for code injection. Furthermore, the fact that 100% of output is not properly escaped is a serious vulnerability, opening the door to cross-site scripting (XSS) attacks. The absence of nonce and capability checks on its single entry point also means that any user, regardless of their role, could potentially trigger its functionality, and there's no built-in protection against CSRF attacks.

Key Concerns

  • Use of create_function
  • 100% of output not properly escaped
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

FnF.FM Bangla Radio Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

FnF.FM Bangla Radio Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
0 prepared
Unescaped Output
6
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

create_functionadd_action( 'widgets_init', create_function('', 'return register_widget("banglafnfradiowidget");') )fnf.fmbangla.php:65

Output Escaping

0% escaped6 total outputs
Attack Surface

FnF.FM Bangla Radio Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[banglafnf] fnf.fmbangla.php:18
WordPress Hooks 2
filterwidget_textfnf.fmbangla.php:19
actionwidgets_initfnf.fmbangla.php:65
Maintenance & Trust

FnF.FM Bangla Radio Maintenance & Trust

Maintenance Signals

WordPress version tested4.6.30
Last updatedAug 25, 2016
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

FnF.FM Bangla Radio Developer Profile

Arifur Rahman

2 plugins · 40 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect FnF.FM Bangla Radio

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
banglafnfradiowidget
Shortcode Output
<iframe height="430" scrolling="no" src="http://bigb.fnf.fm" width="100%"></iframe><iframe height="80" scrolling="no" src="http://bigb.fnf.fm" width="100%"></iframe>
FAQ

Frequently Asked Questions about FnF.FM Bangla Radio