
PledgeMusic Security & Risk Analysis
wordpress.org/plugins/pledgemusicProvides the ability to display your PledgeMusic campaign on your WordPress site.
Is PledgeMusic Safe to Use in 2026?
Generally Safe
Score 85/100PledgeMusic has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The Pledgemusic plugin v1.2.1 exhibits a mixed security posture. On one hand, the absence of known CVEs and a history of zero vulnerabilities is a positive indicator of its past security track record. The static analysis also reveals good practices in other areas, such as the exclusive use of prepared statements for SQL queries and no external HTTP requests, which reduces common attack vectors.
However, significant concerns arise from the static analysis. The presence of the `create_function` is a critical code signal indicating a potential for arbitrary code execution, especially if user-supplied data can influence its parameters. Furthermore, a substantial portion of output is not properly escaped (only 17%), which creates a high risk of cross-site scripting (XSS) vulnerabilities across multiple output points. The complete absence of nonce checks and capability checks on all identified entry points, though the entry points are zero, still indicates a lack of fundamental security measures that would be expected in a production plugin.
In conclusion, while the plugin has a clean vulnerability history and good SQL practices, the identified code signals and output escaping issues represent substantial security weaknesses. The `create_function` and widespread unescaped output present immediate risks that need to be addressed. The lack of any authentication or authorization checks on potential (even if currently zero) entry points suggests a development oversight that could become a problem if the plugin's functionality expands.
Key Concerns
- Dangerous function create_function used
- Low percentage of output properly escaped
- No nonce checks
- No capability checks
PledgeMusic Security Vulnerabilities
PledgeMusic Release Timeline
PledgeMusic Code Analysis
Dangerous Functions Found
Output Escaping
PledgeMusic Attack Surface
WordPress Hooks 5
Maintenance & Trust
PledgeMusic Maintenance & Trust
Maintenance Signals
Community Trust
PledgeMusic Alternatives
Plastic Tunes
plastic-tunes
A Multi-User "Now Playing" plugin that accepts input from iTunes, WinAmp, and many more. Saves your information to your DB and will accomodate multiple users. Widget compatible and highly customizable.
Custom Sidebars – Dynamic Sidebar Classic Widget Area Manager
custom-sidebars
Flexible sidebars for custom classic widget configurations on any page or post. Create custom sidebars with ease!
Image Widget
image-widget
A simple image widget that uses the native WordPress media manager to add image widgets to your site.
Recent Posts Widget With Thumbnails
recent-posts-widget-with-thumbnails
List the most recent posts with post titles, thumbnails, excerpts, authors, categories, dates and more!
Widget Logic
widget-logic
Widget Logic lets you control on which pages widgets appear using WP's conditional tags.
PledgeMusic Developer Profile
1 plugin · 10 total installs
How We Detect PledgeMusic
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/pledgemusic/includes/js/fancybox/jquery.fancybox-1.3.4.pack.js/wp-content/plugins/pledgemusic/includes/js/fancybox/jquery.easing-1.3.pack.js/wp-content/plugins/pledgemusic/includes/js/fancybox/jquery.fancybox-1.3.4.css/wp-content/plugins/pledgemusic/includes/js/pledgemusic.jswp-content/plugins/pledgemusic/includes/js/fancybox/jquery.fancybox-1.3.4.pack.jswp-content/plugins/pledgemusic/includes/js/fancybox/jquery.easing-1.3.pack.jswp-content/plugins/pledgemusic/includes/js/pledgemusic.jspledgemusic/includes/js/fancybox/jquery.fancybox-1.3.4.pack.js?ver=pledgemusic/includes/js/fancybox/jquery.easing-1.3.pack.js?ver=pledgemusic/includes/js/pledgemusic.js?ver=HTML / DOM Fingerprints
id="icon-pm"pledgemusic_data