Player Barra WebRadio Security & Risk Analysis

wordpress.org/plugins/player-barra-webradio

Player barra webradio é um plugin para que você possa inserir a url do player de sua webradio no topo ou rodapé do seu site, sem precisar alterar qual …

100 active installs v0.9.0 PHP 5.3+ WP 3.0+ Updated Nov 7, 2018
audio-playerbarra-playerplayerradiowebradio
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Player Barra WebRadio Safe to Use in 2026?

Generally Safe

Score 85/100

Player Barra WebRadio has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The security posture of the player-barra-webradio plugin v0.9.0 appears to be generally robust from a static analysis perspective, with no identified vulnerabilities or concerning code signals such as dangerous functions, raw SQL queries, or file operations. The absence of known CVEs and a zero-day history further strengthens this impression, indicating a history of responsible development or minimal prior exposure to security scrutiny.

However, a significant concern arises from the complete lack of output escaping (0% properly escaped). This represents a critical weakness, as any data rendered on the front-end or in administrative interfaces could be susceptible to cross-site scripting (XSS) attacks. While the attack surface appears minimal with no AJAX handlers, REST API routes, shortcodes, or cron events exposed without checks, the lack of output sanitization creates a direct vulnerability pathway for malicious code injection.

The plugin's strengths lie in its clean codebase regarding dangerous functions and SQL, alongside no external HTTP requests or bundled libraries that might introduce third-party risks. Nevertheless, the critical failure in output escaping, coupled with a complete absence of nonce and capability checks (which would typically accompany potential entry points), presents a notable risk that undermines the overall security. Until this output sanitization issue is addressed, the plugin should be treated with caution.

Key Concerns

  • Output not properly escaped
  • No nonce checks found
  • No capability checks found
Vulnerabilities
None known

Player Barra WebRadio Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Player Barra WebRadio Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
11
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped11 total outputs
Attack Surface

Player Barra WebRadio Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_menuincludes\menu_opcoes.php:10
actionadmin_initincludes\menu_opcoes.php:15
actiontemplate_redirectplayer-barra-webradio.php:31
Maintenance & Trust

Player Barra WebRadio Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedNov 7, 2018
PHP min version5.3
Downloads5K

Community Trust

Rating60/100
Number of ratings2
Active installs100
Developer Profile

Player Barra WebRadio Developer Profile

matheuscarvalhobr

1 plugin · 100 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Player Barra WebRadio

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
iframe_bariframe_content
Data Attributes
id="iframe_bar"id="iframe_content"
JS Globals
var audiobar
FAQ

Frequently Asked Questions about Player Barra WebRadio