Liza Widget For Spotify and Elementor Security & Risk Analysis

wordpress.org/plugins/liza-spotify-widget-for-elementor

Spotify Widget, Spotify, Easy to use Spotify widget.

1K active installs v3.0 PHP 7.0+ WP 5.2+ Updated Jun 14, 2025
elementormusicspotifyspotify-embedwidgets-for-elementor
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Liza Widget For Spotify and Elementor Safe to Use in 2026?

Generally Safe

Score 100/100

Liza Widget For Spotify and Elementor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9mo ago
Risk Assessment

The plugin "liza-spotify-widget-for-elementor" v3.0 exhibits a generally good security posture based on the provided static analysis and vulnerability history. The absence of dangerous functions, raw SQL queries, and file operations is a strong positive. Furthermore, the plugin demonstrates a commitment to security with a high percentage of properly escaped outputs (85%) and the presence of nonce and capability checks on all identified entry points. The lack of any recorded vulnerabilities, including critical or high severity ones, is a significant indicator of a well-maintained and secure codebase. The plugin's attack surface is limited to three AJAX handlers, all of which are protected by authentication checks, mitigating potential unauthorized access risks. However, a minor concern arises from the presence of external HTTP requests without explicit details on their validation or security implications. While the overall picture is positive, vigilance regarding these external interactions and ensuring the bundled Freemius library is kept up-to-date would further strengthen its security profile. The plugin's history of zero vulnerabilities and a clean taint analysis are excellent indicators of its current security maturity.

Key Concerns

  • Bundled outdated library (Freemius v1.0)
  • External HTTP requests without clear validation context
Vulnerabilities
None known

Liza Widget For Spotify and Elementor Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Liza Widget For Spotify and Elementor Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
18
102 escaped
Nonce Checks
4
Capability Checks
4
File Operations
0
External Requests
3
Bundled Libraries
1

Bundled Libraries

Freemius1.0

Output Escaping

85% escaped120 total outputs
Attack Surface

Liza Widget For Spotify and Elementor Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 3

authwp_ajax_dismiss_ruthless_promoincludes\Admin\Settings.php:18
authwp_ajax_get_now_playing_dataincludes\Ajax\NowPlaying.php:8
noprivwp_ajax_get_now_playing_dataincludes\Ajax\NowPlaying.php:9
WordPress Hooks 13
actionadmin_menuincludes\Admin\Settings.php:8
actionadmin_initincludes\Admin\Settings.php:9
actionadmin_initincludes\Admin\Settings.php:12
actionadmin_initincludes\Admin\Settings.php:13
actionwp_dashboard_setupincludes\Admin\Settings.php:16
actionelementor/widgets/registerincludes\Widgets\WidgetLoader.php:8
actionadmin_noticesincludes\Widgets\WidgetLoader.php:11
actionelementor/editor/footerincludes\Widgets\WidgetLoader.php:17
actionplugins_loadedlizaspotify.php:118
actionadmin_noticeslizaspotify.php:124
actionelementor/elements/categories_registeredlizaspotify.php:135
actionwp_enqueue_scriptslizaspotify.php:188
actionadmin_enqueue_scriptslizaspotify.php:189
Maintenance & Trust

Liza Widget For Spotify and Elementor Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJun 14, 2025
PHP min version7.0
Downloads28K

Community Trust

Rating80/100
Number of ratings8
Active installs1K
Developer Profile

Liza Widget For Spotify and Elementor Developer Profile

Ruthless WP

1 plugin · 1K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Liza Widget For Spotify and Elementor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/liza-spotify-widget-for-elementor/assets/css/spotify-now-playing.css/wp-content/plugins/liza-spotify-widget-for-elementor/assets/css/spotify-artist.css/wp-content/plugins/liza-spotify-widget-for-elementor/assets/js/frontend.js
Script Paths
/wp-content/plugins/liza-spotify-widget-for-elementor/assets/js/frontend.js
Version Parameters
liza-spotify-widget-for-elementor/assets/css/spotify-now-playing.css?ver=liza-spotify-widget-for-elementor/assets/css/spotify-artist.css?ver=liza-spotify-widget-for-elementor/assets/js/frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
liza-spotify-widget-wrapper
Data Attributes
data-widget-type
JS Globals
LizaSpotifyFrontend
FAQ

Frequently Asked Questions about Liza Widget For Spotify and Elementor