
Last.wp Security & Risk Analysis
wordpress.org/plugins/lastwpLast.wp is a Wordpress widget that shows your guests what you've been listening to on Last.fm, via a jQuery plugin!
Is Last.wp Safe to Use in 2026?
Generally Safe
Score 85/100Last.wp has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "lastwp" plugin v0.2 exhibits a mixed security posture. On the positive side, there are no registered CVEs and no identified vulnerabilities in its history. Furthermore, the plugin demonstrates good practices by exclusively using prepared statements for SQL queries and not performing any file operations or external HTTP requests. The absence of a significant attack surface through AJAX handlers, REST API routes, shortcodes, or cron events is also a strength.
However, significant concerns arise from the static code analysis. The presence of the `create_function` is a dangerous function that can lead to remote code execution if not handled with extreme care. More critically, 100% of the plugin's outputs are not properly escaped. This is a major security flaw that can pave the way for Cross-Site Scripting (XSS) attacks, allowing malicious actors to inject arbitrary scripts into the user's browser. The complete lack of nonce and capability checks, while seemingly mitigated by a zero attack surface, leaves the plugin vulnerable if any entry points are accidentally exposed or if future versions introduce them without proper security measures.
While the lack of vulnerability history is a positive indicator, it should not overshadow the critical security weaknesses identified in the code. The unescaped output and the use of `create_function` represent immediate and serious risks that require prompt attention. The plugin's strengths lie in its limited scope and SQL handling, but these are overshadowed by its output sanitization and dangerous function usage.
Key Concerns
- 100% of outputs are not properly escaped
- Use of dangerous function: create_function
- No nonce checks implemented
- No capability checks implemented
Last.wp Security Vulnerabilities
Last.wp Code Analysis
Dangerous Functions Found
Output Escaping
Last.wp Attack Surface
WordPress Hooks 2
Maintenance & Trust
Last.wp Maintenance & Trust
Maintenance Signals
Community Trust
Last.wp Alternatives
last.fm Live!
lastfm-live
Widget to display your recently played tracks from last.fm LIVE! shows any song you play(& scrobble) on your site in realtime.
Music Player for Elementor – Audio Player & Podcast Player
music-player-for-elementor
Audio Player for Elementor – the go-to plugin for adding MP3s, podcasts & playlists. Fully customizable, WooCommerce-ready, and mobile-friendly.
Liza Widget For Spotify and Elementor
liza-spotify-widget-for-elementor
Spotify Widget, Spotify, Easy to use Spotify widget.
TechGasp Music Master
spotify-master
TechGasp Music Master allows you to display in your wordpress website musics, playlists and albums of the cool and "booming" music network Spotify.
Musician's Pack for Elementor – Music Website Widgets & Templates
music-pack-for-elementor
Create stunning music websites with Musician's Pack for Elementor! Powerful widgets & ready-made templates for musicians, bands, DJs, and producers.
Last.wp Developer Profile
2 plugins · 20 total installs
How We Detect Last.wp
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/lastwp/images/lfm_noart.png/wp-content/plugins/lastwp/css/lastwp.css/wp-content/plugins/lastwp/scripts/jquery.lastfm.jsHTML / DOM Fingerprints
widget_lastWPlastWP-lfm_itemlfm_artlfm_playinglfm_songlfm_artistlfm_album+2 morewidget_idjQuery$