HTML5 Lyrics Karaoke Player Security & Risk Analysis

wordpress.org/plugins/html5-lyrics-karaoke-player

HTML5 Lyrics Karaoke Player Plugin enable wordpress users to sing and play song text lyrics. Free Features Supports MP3 formats Supports Text Song …

30 active installs v2.4 PHP + WP 3.0+ Updated May 18, 2021
html5karaokelyricsplayer
43
D · High Risk
CVEs total2
Unpatched2
Last CVENov 18, 2024
Safety Verdict

Is HTML5 Lyrics Karaoke Player Safe to Use in 2026?

High Risk

Score 43/100

HTML5 Lyrics Karaoke Player carries significant security risk with 2 known CVEs, 2 still unpatched. Consider switching to a maintained alternative.

2 known CVEs 2 unpatched Last CVE: Nov 18, 2024Updated 4yr ago
Risk Assessment

The "html5-lyrics-karaoke-player" plugin v2.4 exhibits a mixed security posture. While it demonstrates good practices in its use of prepared statements for SQL queries and a relatively small attack surface, significant concerns arise from its output escaping and vulnerability history. The static analysis revealed that 100% of outputs are not properly escaped, which is a critical flaw that can lead to cross-site scripting (XSS) vulnerabilities. Furthermore, the taint analysis indicates 4 high-severity flows with unsanitized paths, strongly suggesting potential for sensitive data compromise or execution of malicious code. The plugin's history of 2 known medium-severity CVEs, both currently unpatched and primarily related to XSS, reinforces these concerns. The fact that the last vulnerability was very recent (November 2024) suggests a recurring pattern of security weaknesses. While the plugin avoids dangerous functions and external HTTP requests, the lack of proper output escaping and the presence of high-severity taint flows, coupled with unpatched past vulnerabilities, place it at a considerable risk.

Key Concerns

  • Unpatched CVEs
  • High severity taint flows
  • No output escaping
  • No nonce checks
  • No capability checks
Vulnerabilities
2 published

HTML5 Lyrics Karaoke Player Security Vulnerabilities

CVEs by Year

1 CVE in 2014 · unpatched
2014
1 CVE in 2024 · unpatched
2024
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2024-52473medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

HTML5 Lyrics Karaoke Player <= 2.4 - Reflected Cross-Site Scripting

Nov 18, 2024Unpatched
WF-5102d03b-368f-410e-9c0f-a90caa7d28ec-html5-lyrics-karaoke-playermedium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

HTML5 Lyrics Karaoke Player <= 2.4 - Cross-Site Scripting

May 25, 2014Unpatched
Version History

HTML5 Lyrics Karaoke Player Release Timeline

No version history available.
Code Analysis
Analyzed Mar 16, 2026

HTML5 Lyrics Karaoke Player Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
9 prepared
Unescaped Output
46
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
9
External Requests
0
Bundled Libraries
0

SQL Query Safety

90% prepared10 total queries

Output Escaping

0% escaped46 total outputs
Data Flows · Security
5 unsanitized

Data Flow Analysis

5 flows5 with unsanitized paths
<share> (html5lyrics\share.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

HTML5 Lyrics Karaoke Player Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[html5lyrics] index.php:207
WordPress Hooks 3
actionadmin_menuindex.php:78
actionadmin_initindex.php:92
actionwp_enqueue_scriptsindex.php:255
Maintenance & Trust

HTML5 Lyrics Karaoke Player Maintenance & Trust

Maintenance Signals

WordPress version tested5.7.15
Last updatedMay 18, 2021
PHP min version
Downloads6K

Community Trust

Rating60/100
Number of ratings2
Active installs30
Developer Profile

HTML5 Lyrics Karaoke Player Developer Profile

Sandeep Verma

10 plugins · 1K total installs

65
trust score
Avg Security Score
80/100
Avg Patch Time
392 days
View full developer profile
Detection Fingerprints

How We Detect HTML5 Lyrics Karaoke Player

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/html5-lyrics-karaoke-player/html5lyrics/css/ui.tabs.css/wp-content/plugins/html5-lyrics-karaoke-player/html5lyrics/js/ui.tabs.js/wp-content/plugins/html5-lyrics-karaoke-player/html5lyrics/js/jscolor.js/wp-content/plugins/html5-lyrics-karaoke-player/html5lyrics/js/core.js

HTML / DOM Fingerprints

Data Attributes
data-iddata-widthdata-heightdata-fcolordata-bcolordata-tcolor1+6 more
JS Globals
playerInstance
Shortcode Output
[html5lyrics
FAQ

Frequently Asked Questions about HTML5 Lyrics Karaoke Player