
FnF.FM Radio Security & Risk Analysis
wordpress.org/plugins/fnffm-radioFnF.FM is an Online Radio Station that can be used as either a widget or Short code.
Is FnF.FM Radio Safe to Use in 2026?
Generally Safe
Score 85/100FnF.FM Radio has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "fnffm-radio" plugin v1.1 exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for its SQL queries and has no recorded vulnerabilities or CVEs. The attack surface appears limited, with only one shortcode identified as an entry point, and no AJAX handlers or REST API routes were found without authentication checks. Furthermore, there are no file operations or external HTTP requests, which generally reduces the potential for certain types of attacks.
However, several significant concerns emerge from the static analysis. The use of the `create_function` is a critical security anti-pattern, as it can be exploited for code injection if any part of the dynamically created function's code is user-controlled. More alarmingly, a complete lack of output escaping across all identified outputs (6 in total) means that any dynamic content displayed by the plugin is highly susceptible to Cross-Site Scripting (XSS) attacks. The absence of nonce checks and capability checks on its limited entry points also presents a vulnerability, potentially allowing for unauthorized actions or information disclosure if exploited.
Given the absence of historical vulnerabilities, it's difficult to infer patterns beyond the current code. However, the presence of `create_function` and especially the widespread lack of output escaping are serious flaws that demand immediate attention. While the plugin's current lack of public CVEs is a positive indicator, the identified code-level weaknesses represent a substantial risk that could lead to critical security incidents like XSS and potential code execution.
Key Concerns
- Use of dangerous function create_function
- No output escaping
- No nonce checks
- No capability checks
FnF.FM Radio Security Vulnerabilities
FnF.FM Radio Code Analysis
Dangerous Functions Found
Output Escaping
FnF.FM Radio Attack Surface
Shortcodes 1
WordPress Hooks 2
Maintenance & Trust
FnF.FM Radio Maintenance & Trust
Maintenance Signals
Community Trust
FnF.FM Radio Alternatives
AAM Online Bangla Radio
aam-online-bangla-radio
A Radio Player For All Online Bangla Radio Station. Can Be Used in widget and Sortcode.
Bangla Radio Abirvab
bangla-radio-abirvab
Easily add a 24/7 Bangla Radio to your website.
FnF.FM Bangla Radio
fnffm-bangla-radio
FnF.FM Bangla Radio is an Online Radio Station that can be used as either a widget or Short code.
Custom Sidebars – Dynamic Sidebar Classic Widget Area Manager
custom-sidebars
Flexible sidebars for custom classic widget configurations on any page or post. Create custom sidebars with ease!
Image Widget
image-widget
A simple image widget that uses the native WordPress media manager to add image widgets to your site.
FnF.FM Radio Developer Profile
2 plugins · 40 total installs
How We Detect FnF.FM Radio
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
fnffmradiowidget<iframe height="430" scrolling="no" src="http://big.fnf.fm" width="100%"></iframe><iframe height="80" scrolling="no" src="http://big.fnf.fm" width="100%"></iframe>