
Plastic Tunes Security & Risk Analysis
wordpress.org/plugins/plastic-tunesA Multi-User "Now Playing" plugin that accepts input from iTunes, WinAmp, and many more. Saves your information to your DB and will accomodate multiple users. Widget compatible and highly customizable.
Is Plastic Tunes Safe to Use in 2026?
Generally Safe
Score 85/100Plastic Tunes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'plastic-tunes' v1.4 plugin exhibits a mixed security posture. While it boasts a zero attack surface from traditional entry points like AJAX handlers, REST API routes, and shortcodes, and has no known CVEs, significant concerns arise from its static analysis. The plugin's output escaping is alarmingly low, with only 29% of outputs properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. Furthermore, the taint analysis reveals 9 flows with unsanitized paths, including 3 classified as high severity. This suggests that user-supplied data is not being adequately validated or sanitized before being used in potentially sensitive operations. The lack of any capability checks or nonce checks on entry points, though currently zero, means that if any entry points were to be introduced in future versions, they would likely be unprotected by default. The plugin's SQL query handling is also a concern, with only 18% of queries using prepared statements, increasing the risk of SQL injection. The absence of any recorded vulnerability history might suggest a lack of active exploitation or discovery, but it does not negate the clear code-level risks present. The plugin's strengths lie in its lack of known vulnerabilities and a seemingly limited attack surface. However, the critical weaknesses in output escaping and taint handling, coupled with less secure SQL practices, demand immediate attention.
Key Concerns
- High severity taint flows
- Unsanitized paths in taint analysis
- Low output escaping percentage
- Low prepared statement usage for SQL
- No capability checks
- No nonce checks
Plastic Tunes Security Vulnerabilities
Plastic Tunes Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Plastic Tunes Attack Surface
WordPress Hooks 3
Maintenance & Trust
Plastic Tunes Maintenance & Trust
Maintenance Signals
Community Trust
Plastic Tunes Alternatives
Fuse Social Floating Sidebar
fuse-social-floating-sidebar
This plugin allows you to add social media floating sidebar icons connected with your social media profiles.
Simple Image Widget
simple-image-widget
A simple widget that makes it a breeze to add images to your sidebars.
Social Media Icon Widget
new-social-media-widget
Add social media icon links to your sidebar with customizable styles, colors, hover effects, and animations.
FloatySocial – Awesome Social Floating Sidebar
floatysocial-awesome-social-floating-sidebar
This plugin lets you add floating sidebar icons to your site that link directly to your social media profiles.
Javascript Flickr Badge
javascript-flickr-badge
Displays photos from Flickr, with optional tag filtering, with pure client-side javascript. Several eye-catching effects available.
Plastic Tunes Developer Profile
2 plugins · 90 total installs
How We Detect Plastic Tunes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/plastic-tunes/plastic.css