
LS IceCast ONAIR Security & Risk Analysis
wordpress.org/plugins/ls-icecast-onairShortcode to display onair song fetched from IceCast server (v2).
Is LS IceCast ONAIR Safe to Use in 2026?
Generally Safe
Score 85/100LS IceCast ONAIR has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "ls-icecast-onair" plugin v1.1.1 exhibits a generally positive security posture, with no known vulnerabilities and a clean vulnerability history. The static analysis reveals strong adherence to secure coding practices in several areas, most notably the complete absence of dangerous functions and the exclusive use of prepared statements for all SQL queries. Furthermore, the plugin demonstrates good practice by implementing capability checks for its entry points and avoiding the bundling of external libraries. The limited attack surface, with only one shortcode and one cron event, both appearing to be protected, is also a positive indicator.
However, a significant concern arises from the complete lack of output escaping for all detected output points. This represents a serious security weakness, as it leaves the plugin highly susceptible to Cross-Site Scripting (XSS) attacks. Any data displayed to users that originates from user input or external sources, even if processed securely, could be manipulated to inject malicious scripts. The absence of nonce checks on its entry points, while noted as having zero unprotected entry points, means that even if protected by capability checks, a lack of nonces could still expose it to certain types of CSRF attacks if not carefully implemented within the capability check logic.
In conclusion, while the plugin has a strong foundation in preventing common vulnerabilities like SQL injection and avoids dangerous functions, the unaddressed output escaping issue is a critical flaw that needs immediate attention. The lack of historical vulnerabilities is reassuring, but it doesn't negate the current, identified risks. Addressing the output escaping is paramount to securing this plugin.
Key Concerns
- 0% output escaping
- 0 Nonce checks
LS IceCast ONAIR Security Vulnerabilities
LS IceCast ONAIR Code Analysis
Output Escaping
Data Flow Analysis
LS IceCast ONAIR Attack Surface
Shortcodes 1
WordPress Hooks 4
Scheduled Events 1
Maintenance & Trust
LS IceCast ONAIR Maintenance & Trust
Maintenance Signals
Community Trust
LS IceCast ONAIR Alternatives
Shoutcast Icecast HTML5 Radio Player
shoutcast-icecast-html5-radio-player
A secure HTML5 radio player for Shoutcast, Icecast, and podcast streams with social sharing.
StreamCast – Live Radio Streaming Player
streamcast
StreamCast allows you to play IceCast, Shoutcast, Radionomy, RadioJar, RadioCo and more beautifully inside WordPress.
WPRadio – WordPress Radio Streaming Plugin
wpradio
An entire radio streaming platform within your WordPress site.
Now playing for AzuraCast
now-playing-widget-fuer-azuracast-stationen
Display currently played song of an AzuraCast instance in a sidebar.
Radio Player Page
radio-player-page
Dedicated player pages for your radio streams, with program scheduling and continuous playback.
LS IceCast ONAIR Developer Profile
4 plugins · 1K total installs
How We Detect LS IceCast ONAIR
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ls-icecast-onair/ls-icecast-onair.jsls-icecast-onair.jsHTML / DOM Fingerprints
icecast_onair_outericecast_onair_innericecast_onair_liveid="icecast_onair_"ls_icecast_onair_url<span class="icecast_onair_outer"><span class="icecast_onair_inner id="