
Last.fm RPS Security & Risk Analysis
wordpress.org/plugins/lastfm-rpsWidget Plugin that lists your recently listened songs on your sidebar with album or artist images and text.
Is Last.fm RPS Safe to Use in 2026?
Generally Safe
Score 85/100Last.fm RPS has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "lastfm-rps" plugin version 2.0.0 exhibits a generally strong security posture based on the provided static analysis. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events that expose an attack surface, and therefore no unprotected entry points. The plugin also demonstrates good practices by exclusively using prepared statements for its SQL queries and reporting no file operations or external HTTP requests. Crucially, there is no known vulnerability history, suggesting a well-maintained or less targeted plugin.
However, there are a few areas of concern. The presence of the `create_function` function is a significant red flag, as it can be a vector for code injection if used with untrusted input. Furthermore, the low percentage of properly escaped output (16%) indicates a high risk of cross-site scripting (XSS) vulnerabilities, especially if any of the unescaped outputs process user-supplied data. The absence of nonce checks and capability checks on any potential (though not identified) entry points, coupled with a lack of taint analysis data, leaves room for potential vulnerabilities that might not have been caught by the static analysis.
In conclusion, while the plugin boasts a clean vulnerability history and a limited attack surface, the identified use of `create_function` and the widespread lack of output escaping are serious weaknesses that require immediate attention. These issues, if exploited, could lead to significant security breaches, despite the absence of known CVEs.
Key Concerns
- Use of dangerous function create_function
- Low percentage of properly escaped output
- No nonce checks
- No capability checks
Last.fm RPS Security Vulnerabilities
Last.fm RPS Code Analysis
Dangerous Functions Found
Output Escaping
Last.fm RPS Attack Surface
WordPress Hooks 2
Maintenance & Trust
Last.fm RPS Maintenance & Trust
Maintenance Signals
Community Trust
Last.fm RPS Alternatives
Last.fm for WordPress
lastfm-for-wordpress
Last.fm for WordPress displays your recently listened tracks in your WordPress blog.
F13 Last.fm album Shortcode
f13-lastfm-album-shortcode
Add information to you blog about a musical album using shortcode.
Last.FM Recent Tracks – WordPress Plugin
recent-tracks-lastfm
With this plugin you can add your recent scrobbled tracks on Last.FM to your site.
Content Views – Post Grid & Filter, Recent Posts, Category Posts … (Shortcode, Gutenberg Blocks, and Widgets for Elementor)
content-views-query-and-display-post-page
Easy to show posts, pages, custom posts in customizable grid, list, slider, accordion... Available as Widgets (for Elementor), Shortcode, and Blocks.
Recent Posts Widget With Thumbnails
recent-posts-widget-with-thumbnails
List the most recent posts with post titles, thumbnails, excerpts, authors, categories, dates and more!
Last.fm RPS Developer Profile
1 plugin · 10 total installs
How We Detect Last.fm RPS
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/lastfm-rps/css/style.csslastfm-rps/css/style.css?ver=HTML / DOM Fingerprints
lastfm-rps-widgetlastfm-rps-badgelastfm-rps-infolastfm-rps-avatardata-lastfm-rps-userdata-lastfm-rps-sizedata-lastfm-rps-positiondata-lastfm-rps-colordata-lastfm-rps-showbadgedata-lastfm-rps-badgeposition+9 more