
Search for Spotify Security & Risk Analysis
wordpress.org/plugins/kirilkirkov-spotify-searchSearch Spotify for tracks, albums, playlists, and artists from your WordPress site.
Is Search for Spotify Safe to Use in 2026?
Generally Safe
Score 100/100Search for Spotify has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "kirilkov-spotify-search" plugin v2.0 exhibits a generally good security posture, with no known vulnerabilities or critical code signals. The static analysis indicates a small attack surface, with only two AJAX handlers, and importantly, none of these appear to be unprotected by authentication checks. Furthermore, all SQL queries are properly prepared, and there are no observed file operations or external HTTP requests, which are common vectors for exploitation. The presence of a nonce check on at least one entry point is also a positive sign. However, a significant concern arises from the taint analysis, which reveals three flows with unsanitized paths. Although these are not flagged as critical or high severity in this analysis, unsanitized paths represent a potential risk for directory traversal or other path manipulation vulnerabilities, especially if they interact with user-supplied input. The plugin's vulnerability history shows no recorded CVEs, which is excellent, suggesting a mature and well-maintained codebase or a low profile for attackers. In conclusion, while the plugin benefits from robust practices like prepared statements and a limited attack surface, the presence of unsanitized paths in taint analysis warrants careful investigation to ensure user input is adequately validated and escaped before being used in file system operations or other sensitive contexts. The lack of capability checks on AJAX handlers is a potential weakness, as it relies solely on nonce checks for authorization.
Key Concerns
- Unsanitized paths in taint analysis
- Missing capability checks on AJAX handlers
- Low percentage of properly escaped output
Search for Spotify Security Vulnerabilities
Search for Spotify Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Search for Spotify Attack Surface
AJAX Handlers 2
WordPress Hooks 4
Maintenance & Trust
Search for Spotify Maintenance & Trust
Maintenance Signals
Community Trust
Search for Spotify Alternatives
PowerPress Podcasting plugin by Blubrry
powerpress
No. 1 Podcasting plugin for WordPress.
Podcast Subscribe Buttons
podcast-subscribe-buttons
Add beautiful podcast subscribe buttons anywhere.
Sp*tify Play Button for WordPress
spotify-play-button-for-wordpress
Now with Gutenberg block!
Anchor Episodes Index (Spotify for Podcasters)
anchor-episodes-index
A lightweight plugin that allows you to output an anchor.fm podcast player on your site that includes an episode index. Just add two URL's on the …
Liza Widget For Spotify and Elementor
liza-spotify-widget-for-elementor
Spotify Widget, Spotify, Easy to use Spotify widget.
Search for Spotify Developer Profile
2 plugins · 20 total installs
How We Detect Search for Spotify
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/kirilkirkov-spotify-search/Includes/Admin/Assets/core.css/wp-content/plugins/kirilkirkov-spotify-search/Includes/Admin/Assets/admin.css/wp-content/plugins/kirilkirkov-spotify-search/Includes/Admin/Assets/admin.js/wp-content/plugins/kirilkirkov-spotify-search/Includes/Public/spotify_search.js/wp-content/plugins/kirilkirkov-spotify-search/Includes/Public/spotify_search.css/Includes/Admin/Assets/admin.js/Includes/Public/spotify_search.jskirilkirkov-spotify-search/Includes/Admin/Assets/core.css?ver=kirilkirkov-spotify-search/Includes/Admin/Assets/admin.css?ver=kirilkirkov-spotify-search/Includes/Admin/Assets/admin.js?ver=kirilkirkov-spotify-search/Includes/Public/spotify_search.js?ver=kirilkirkov-spotify-search/Includes/Public/spotify_search.css?ver=HTML / DOM Fingerprints
spotify-search-formdata-nonceajax_object<div class="spotify-search-form">