
Jock On Air Now (JOAN) Security & Risk Analysis
wordpress.org/plugins/joanThe ultimate radio station scheduling plugin. Manage DJs, display current shows, and engage your audience with real-time on-air information.
Is Jock On Air Now (JOAN) Safe to Use in 2026?
Generally Safe
Score 95/100Jock On Air Now (JOAN) has a strong security track record. Known vulnerabilities have been patched promptly.
The "joan" plugin v6.1.2 presents a mixed security posture. While it demonstrates some good practices, such as a relatively low number of external HTTP requests and file operations, significant concerns arise from its attack surface and historical vulnerability patterns.
The static analysis reveals a substantial attack surface with 21 entry points, of which 8 lack authentication checks. This is a critical weakness, as it leaves these entry points open to unauthorized access and potential exploitation. Furthermore, 59% of SQL queries use prepared statements, which is a positive, but the remaining 41% do not, potentially exposing the database to SQL injection vulnerabilities. Similarly, only 63% of output is properly escaped, indicating a risk of Cross-Site Scripting (XSS) vulnerabilities.
The vulnerability history is particularly concerning, with a total of 4 known CVEs, including one high-severity vulnerability. The common vulnerability types (Missing Authorization, CSRF, XSS) align with the weaknesses identified in the static analysis, suggesting recurring issues. The fact that the last vulnerability was in October 2025 and there are no currently unpatched vulnerabilities is a positive sign, but the past record indicates a need for continuous vigilance and robust security practices. Overall, while the plugin has some strengths, the significant number of unprotected entry points and the historical vulnerability profile warrant caution.
Key Concerns
- Unprotected AJAX handlers
- SQL queries not using prepared statements
- Improper output escaping
- High historical vulnerability count
- High severity historical vulnerability
Jock On Air Now (JOAN) Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
Jock On Air Now (JOAN) <= 6.0.4 - Missing Authorization
Jock on air now <= 5.6.1 - Cross-Site Request Forgery to Settings Update
Jock on air now <= 5.6.2 - Unauthenticated Stored Cross-Site Scripting
Jock on air now <= 5.6.1 - Reflected Cross-Site Scripting
Jock On Air Now (JOAN) Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Jock On Air Now (JOAN) Attack Surface
AJAX Handlers 15
Shortcodes 6
WordPress Hooks 45
Maintenance & Trust
Jock On Air Now (JOAN) Maintenance & Trust
Maintenance Signals
Community Trust
Jock On Air Now (JOAN) Alternatives
Radio Station by netmix® – Manage and play your Show Schedule in WordPress!
radio-station
Radio Station lets you build and manage a Show Schedule for a radio station or Internet broadcaster's WordPress website.
Stream Player by netmix® – Streaming audio for WordPress!
stream-player
Free, open source streaming audio player plugin by netmix®. Works with Icecast, Shoutcast, and Live 365 streams. For additional features, upgrade to S …
ownRadio
com-netvoxlab-ownradio
Broadcast radio ownRadio. Listen to your favorite music only.
Tz Weekly Radio Schedule
tz-wrs-core
The Weekly Radio Schedule provides an ajax-driven schedule page, creates Team roles, presents up-to-date schedule information, allows easy allocation …
Hostinger Tools
hostinger
Simplified WordPress management. Manage site info, maintenance, security, & redirects.
Jock On Air Now (JOAN) Developer Profile
3 plugins · 540 total installs
How We Detect Jock On Air Now (JOAN)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/joan/assets/css/joan-styles.css/wp-content/plugins/joan/assets/js/joan-scripts.js/wp-content/plugins/joan/assets/js/joan-scripts.jsjoan/assets/css/joan-styles.css?ver=joan/assets/js/joan-scripts.js?ver=HTML / DOM Fingerprints
joan-schedule-wrapdata-joan-languageJOAN_SCRIPT_PARAMS[joan-schedule[joan-elementor-widget