
Podlove Subscribe button Security & Risk Analysis
wordpress.org/plugins/podlove-subscribe-buttonPodlove Subscribe button allows your users to easily select a podcast feed and pass it along to their favorite podcast app.
Is Podlove Subscribe button Safe to Use in 2026?
Generally Safe
Score 95/100Podlove Subscribe button has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The Podlove Subscribe Button plugin v1.3.12 presents a mixed security posture. While it boasts a relatively small attack surface with no unprotected entry points and a significant percentage of SQL queries using prepared statements, there are areas of concern. The presence of the `unserialize` function is a significant red flag, as it can lead to Remote Code Execution (RCE) vulnerabilities if not handled with extreme care and input validation. Additionally, 51% of output escaping is a concern, suggesting potential for Cross-Site Scripting (XSS) vulnerabilities where user-supplied data might be rendered without proper sanitization. The vulnerability history reveals a pattern of past security issues, including SQL Injection, XSS, and CSRF, with a high-severity vulnerability recorded as recently as September 2025. The fact that all past CVEs are currently patched is positive, but the recurring types of vulnerabilities and the historical presence of a high-severity flaw indicate a need for diligent security practices from the developers. Overall, while the immediate code analysis shows no critical active threats, the potential for issues due to `unserialize` and the historical vulnerability patterns warrant caution.
Key Concerns
- Dangerous function unserialize present
- Output escaping is not fully implemented (51% escaped)
- 1 High severity vulnerability in history
- 3 Medium severity vulnerabilities in history
- Taint analysis shows unsanitized paths
Podlove Subscribe button Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
Podlove Subscribe button <= 1.3.11 - Authenticated (Contributor+) Stored Cross-Site Scripting
Podlove Subscribe button <= 1.3.10 - Authenticated (Contributor+) SQL Injection
Podlove Subscribe button <= 1.3.7 - Authenticated (Administrator+) Stored Cross-Site Scripting
Podlove Subscribe button <= 1.3.7 - Cross-Site Request Forgery via save function
Podlove Subscribe button Release Timeline
Podlove Subscribe button Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Podlove Subscribe button Attack Surface
Shortcodes 1
WordPress Hooks 9
Maintenance & Trust
Podlove Subscribe button Maintenance & Trust
Maintenance Signals
Community Trust
Podlove Subscribe button Alternatives
Subscribe Button by AddToAny
add-to-any-subscribe
Help visitors subscribe to your blog using email or any feed reader, such as Feedly, The Old Reader, Yahoo!, AOL, and many more feed services.
Buttonizer – Social Media Share Buttons, Social Icons, & Social Feeds
facebook-pagelike-widget
Floating Social Media Icons, Sticky Share Buttons, Facebook Feeds, & Popup builder. Also, create Call, Email, SMS, & Contact buttons to increa …
Contact Form & SMTP Plugin for WordPress by PirateForms
pirate-forms
A simple and effective WordPress contact form & SMTP plugin. Compatible with best themes out there, is both a secure and responsive contact form p …
PowerPress Podcasting plugin by Blubrry
powerpress
No. 1 Podcasting plugin for WordPress.
Podcast Player – Your Podcasting Companion
podcast-player
Showcase your podcast only using podcasting feed url. Use widget, shortcode or editor block to display podcast player anywhere on your site.
Podlove Subscribe button Developer Profile
1 plugin · 2K total installs
How We Detect Podlove Subscribe button
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/podlove-subscribe-button/style.css/wp-content/plugins/podlove-subscribe-button/js/admin.js/wp-content/plugins/podlove-subscribe-button/js/admin.jspodlove-subscribe-button/style.css?ver=podlove-subscribe-button-admin-tools?ver=HTML / DOM Fingerprints
podlove-subscribe-button-containerdata-podlove-subscribe-button-buttondata-podlove-subscribe-button-sizedata-podlove-subscribe-button-styledata-podlove-subscribe-button-formatdata-podlove-subscribe-button-colordata-podlove-subscribe-button-autowidth+1 morepodlove_subscribe_button_default_sizepodlove_subscribe_button_default_autowidthpodlove_subscribe_button_default_colorpodlove_subscribe_button_default_stylepodlove_subscribe_button_default_format[podlove-subscribe-button]