
Last FM Security & Risk Analysis
wordpress.org/plugins/last-fmPermits the display in your sidebar of your most recent listened to tracks
Is Last FM Safe to Use in 2026?
Generally Safe
Score 85/100Last FM has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'last-fm' v1.0.3 plugin exhibits a mixed security posture. On the positive side, the absence of known vulnerabilities in its history and a lack of dangerous functions, SQL queries without prepared statements, and file operations are strong indicators of good development practices regarding common attack vectors. The presence of a nonce check and a single external HTTP request are also positive signs. However, a significant concern arises from the static analysis of output escaping, where 100% of outputs are not properly escaped. This is a critical flaw that can lead to Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the website. The taint analysis, while not reporting critical or high severity flows, did reveal 4 flows with unsanitized paths, which, combined with the unescaped output, presents a tangible risk of XSS if these paths involve user-controllable data.
Key Concerns
- 100% of outputs not properly escaped
- Taint flows with unsanitized paths
Last FM Security Vulnerabilities
Last FM Code Analysis
Output Escaping
Data Flow Analysis
Last FM Attack Surface
WordPress Hooks 3
Maintenance & Trust
Last FM Maintenance & Trust
Maintenance Signals
Community Trust
Last FM Alternatives
Recent LastFm Tracks
recent-lastfm-tracks
This simple widget includes your LastFm recent tracks into the sidebar.
Last.FM Recent Tracks – WordPress Plugin
recent-tracks-lastfm
With this plugin you can add your recent scrobbled tracks on Last.FM to your site.
Last.fm for WordPress
lastfm-for-wordpress
Last.fm for WordPress displays your recently listened tracks in your WordPress blog.
last.fm Live!
lastfm-live
Widget to display your recently played tracks from last.fm LIVE! shows any song you play(& scrobble) on your site in realtime.
Last.fm RPS
lastfm-rps
Widget Plugin that lists your recently listened songs on your sidebar with album or artist images and text.
Last FM Developer Profile
4 plugins · 4K total installs
How We Detect Last FM
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.