
PlayMe Security & Risk Analysis
wordpress.org/plugins/playmeEmbeddable Song Request Form for Radio Stations
Is PlayMe Safe to Use in 2026?
Generally Safe
Score 92/100PlayMe has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "playme" v0.2.8 plugin exhibits a concerning security posture primarily due to its unprotected entry points and the complete absence of prepared statements for its SQL queries. While the plugin doesn't appear to have a history of known vulnerabilities, this could be more a reflection of its limited exposure or detection rather than inherent security. The static analysis reveals a significant attack surface with 4 out of 5 entry points lacking authentication checks. This means that potentially any user, regardless of their role or logged-in status, could trigger these functions, opening the door for various attacks. The critical weakness lies in the 5 SQL queries which are all executed without prepared statements. This makes the plugin highly susceptible to SQL injection vulnerabilities. While the plugin does perform capability checks and has a good output escaping rate, these strengths are overshadowed by the fundamental flaws in handling user input for database operations and the lack of authorization on its AJAX handlers. Therefore, despite a clean vulnerability history, the plugin should be treated with extreme caution and is not recommended for use without significant remediation.
Key Concerns
- Unprotected AJAX handlers
- SQL queries without prepared statements
- No nonce checks on AJAX handlers
PlayMe Security Vulnerabilities
PlayMe Code Analysis
SQL Query Safety
Output Escaping
PlayMe Attack Surface
AJAX Handlers 4
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
PlayMe Maintenance & Trust
Maintenance Signals
Community Trust
PlayMe Alternatives
Meks Audio Player
meks-audio-player
Easily enhance your podcast, music or any audio files with a full-featured and customizable sticky audio player.
Music Player for WooCommerce
music-player-for-woocommerce
Music Player for WooCommerce includes the MediaElement.js music player in the pages of the products with audio files associated.
Radio Station by netmix® – Manage and play your Show Schedule in WordPress!
radio-station
Radio Station lets you build and manage a Show Schedule for a radio station or Internet broadcaster's WordPress website.
Transcoder
transcoder
Transcoding services for ANY WordPress website. Convert audio/video files of any format to a web-friendly format (mp3/mp4).
WP Chords
wp-chords
WP Chords allows you to format and display the chords on your blog including mobile friendly interface and AMP functionality.
PlayMe Developer Profile
5 plugins · 320 total installs
How We Detect PlayMe
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/playme/styles.css/wp-content/plugins/playme/scripts.js/wp-content/plugins/playme/scripts.jsplayme/scripts.js?ver=1.1HTML / DOM Fingerprints
PlayMeAdminPlayMe_submissionsplayme_timerPlayMe_refreshPlayMe_recaptchadata-secondsajax_objectPlayMe/wp-json/playme/v1/settings/wp-json/playme/v1/requests