
Last.fm for WordPress Security & Risk Analysis
wordpress.org/plugins/lastfm-for-wordpressLast.fm for WordPress displays your recently listened tracks in your WordPress blog.
Is Last.fm for WordPress Safe to Use in 2026?
Generally Safe
Score 85/100Last.fm for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "lastfm-for-wordpress" plugin version 1.3.3 exhibits a mixed security posture. On the positive side, the static analysis reveals no identified dangerous functions, no direct SQL queries (all use prepared statements), no file operations, and no external HTTP requests, which are all good security indicators. Furthermore, the vulnerability history shows no known CVEs, suggesting a relatively clean past. However, a significant concern arises from the complete lack of output escaping for all detected output points. This indicates a strong potential for cross-site scripting (XSS) vulnerabilities if any user-supplied data reaches these output points without proper sanitization, even if the current static analysis did not flag specific taint flows. The absence of nonce and capability checks on entry points, although the entry point count is zero, is a theoretical weakness if new entry points were introduced in the future without proper security considerations.
Key Concerns
- All outputs are unescaped
Last.fm for WordPress Security Vulnerabilities
Last.fm for WordPress Code Analysis
Output Escaping
Last.fm for WordPress Attack Surface
WordPress Hooks 3
Maintenance & Trust
Last.fm for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
Last.fm for WordPress Alternatives
Last.fm RPS
lastfm-rps
Widget Plugin that lists your recently listened songs on your sidebar with album or artist images and text.
F13 Last.fm album Shortcode
f13-lastfm-album-shortcode
Add information to you blog about a musical album using shortcode.
Recently Viewed Product for WooCommerce
recently-viewed-products-for-woocommerce
Recently Viewed Products for WooCommerce Listing page, you can easily add recently viewed product section by activate the plugin.
Posts Viewed Recently
posts-viewed-recently
Posts Viewed Recently plugin shows recently viewed posts or pages by a visitor as a responsive sidebar widget or on a page/post using the shortcode.
DD Last Viewed
dd-lastviewed
Shows the users recently viewed/visited posts, filtered on types or terms, in a widget.
Last.fm for WordPress Developer Profile
8 plugins · 1K total installs
How We Detect Last.fm for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/lastfm-for-wordpress/css/lastfm.css/wp-content/plugins/lastfm-for-wordpress/js/lastfm.js/wp-content/plugins/lastfm-for-wordpress/js/lastfm.jslastfm-for-wordpress/css/lastfm.css?ver=lastfm-for-wordpress/js/lastfm.js?ver=HTML / DOM Fingerprints
lastfmlastfm-itemlastfm-linklastfm-timestamplastfm_title_linklastfm_fieldlastfm-numberlastfm-submitlastfm_options