
last.fm Live! Security & Risk Analysis
wordpress.org/plugins/lastfm-liveWidget to display your recently played tracks from last.fm LIVE! shows any song you play(& scrobble) on your site in realtime.
Is last.fm Live! Safe to Use in 2026?
Generally Safe
Score 85/100last.fm Live! has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'lastfm-live' plugin v0.2.6 presents a mixed security posture. On the positive side, there are no known CVEs, and the plugin demonstrates good practices regarding SQL queries, exclusively using prepared statements. Furthermore, the static analysis shows no critical or high-severity taint flows, and no direct file operations or external HTTP requests were detected without potential checks. However, several concerning signals emerge from the code analysis. The presence of the `create_function` is a significant red flag due to its potential for code injection if user input is directly passed to it. Additionally, a substantial portion of output (36%) is not properly escaped, posing a risk of Cross-Site Scripting (XSS) vulnerabilities. The complete absence of nonce and capability checks across all identified entry points is another major concern, making the plugin highly susceptible to CSRF attacks and privilege escalation if any user-controlled input is processed without proper authorization or verification. While the plugin has no reported vulnerabilities historically, the significant code-level weaknesses suggest an underdeveloped security awareness in its development. The lack of any security checks on entry points, combined with the dangerous function and unescaped output, indicates a potential for exploitable vulnerabilities that have perhaps not yet been discovered or reported.
Key Concerns
- Use of dangerous function: create_function
- Significant unescaped output detected
- Missing nonce checks on all entry points
- Missing capability checks on all entry points
last.fm Live! Security Vulnerabilities
last.fm Live! Code Analysis
Dangerous Functions Found
Output Escaping
last.fm Live! Attack Surface
WordPress Hooks 1
Maintenance & Trust
last.fm Live! Maintenance & Trust
Maintenance Signals
Community Trust
last.fm Live! Alternatives
Last.wp
lastwp
Last.wp is a Wordpress widget that shows your guests what you've been listening to on Last.fm, via a jQuery plugin!
Tawk.To Live Chat
tawkto-live-chat
(OFFICIAL tawk.to plugin) Instantly chat with visitors on your website with the free tawk.to chat widget. Website: http://tawk.to
Music Player for Elementor – Audio Player & Podcast Player
music-player-for-elementor
Audio Player for Elementor – the go-to plugin for adding MP3s, podcasts & playlists. Fully customizable, WooCommerce-ready, and mobile-friendly.
LiveChat – Live Chat Plugin for WP Websites
wp-live-chat-software-for-wordpress
Best live chat and help desk plugin for WordPress websites. Add the LiveChat widget to engage visitors and provide real‑time customer support! 🚀
Pure Chat – Live Chat & More!
pure-chat
Pure Chat provides a Live Chat plugin with Unlimited Chats for your website!
last.fm Live! Developer Profile
1 plugin · 10 total installs
How We Detect last.fm Live!
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/lastfm-live/styles.css/wp-content/plugins/lastfm-live/lastfmlive.jslastfm-live/styles.css?ver=lastfm-live/lastfmlive.js?ver=HTML / DOM Fingerprints
lastfmlive-now-playingdata-lastfmlive-usernamedata-lastfmlive-tracklimitdata-lastfmlive-livetxtlastfmliveprototype