Lyric Wiki Search Widget Security & Risk Analysis

wordpress.org/plugins/lyricwikisearch

Adds a sidebar widget to search for song lyrics on the LyricWiki.org site.

10 active installs v0.8 PHP + WP 2.0.2+ Updated Aug 16, 2007
lyricsmusicsearchwidget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Lyric Wiki Search Widget Safe to Use in 2026?

Generally Safe

Score 85/100

Lyric Wiki Search Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 18yr ago
Risk Assessment

The "lyricwikisearch" v0.8 plugin exhibits a generally low-risk security posture based on the provided static analysis and vulnerability history. The absence of any identified CVEs, along with the zero recorded vulnerabilities in its history, suggests a history of secure development or at least a lack of publicly disclosed issues. Furthermore, the static analysis reveals no concerning code signals such as dangerous functions, raw SQL queries, or external HTTP requests. The plugin also appears to have a minimal attack surface with no identified entry points such as AJAX handlers, REST API routes, shortcodes, or cron events that are exposed without authentication or permission checks.

However, a significant concern arises from the output escaping. The analysis indicates that 100% of the total outputs are not properly escaped. This is a critical oversight that can lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is displayed on the frontend without proper sanitization. While other security aspects appear to be handled well, this single weakness poses a substantial risk that could be exploited to inject malicious scripts into the website, impacting users and potentially the site's integrity. Therefore, despite its strengths in other areas, the lack of output escaping necessitates immediate attention.

Key Concerns

  • 0% of output properly escaped
Vulnerabilities
None known

Lyric Wiki Search Widget Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Lyric Wiki Search Widget Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

Lyric Wiki Search Widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped6 total outputs
Attack Surface

Lyric Wiki Search Widget Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionwidgets_initLyricWikiSearch.php:90
Maintenance & Trust

Lyric Wiki Search Widget Maintenance & Trust

Maintenance Signals

WordPress version tested2.1
Last updatedAug 16, 2007
PHP min version
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Lyric Wiki Search Widget Developer Profile

jfranzone

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Lyric Wiki Search Widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
searchButton
Data Attributes
id="searchInput"id="searchform"
FAQ

Frequently Asked Questions about Lyric Wiki Search Widget