
PowerFM Radyo Security & Risk Analysis
wordpress.org/plugins/powerfm-radyoBu eklenti sayesinde Wordpress blogunuzda PowerFM kurulmaktadır.
Is PowerFM Radyo Safe to Use in 2026?
Generally Safe
Score 85/100PowerFM Radyo has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "powerfm-radyo" v2.0 exhibits a generally strong security posture based on the provided static analysis. The absence of identified AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the attack surface. Furthermore, the code signals indicate a lack of dangerous functions, file operations, and external HTTP requests, which are common vectors for exploits. The consistent use of prepared statements for SQL queries is a significant strength, mitigating SQL injection risks.
However, a critical concern emerges from the output escaping analysis, where 100% of identified outputs are not properly escaped. This presents a high risk of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the website. The complete lack of nonce and capability checks is also noteworthy, especially given the absence of specific entry points analyzed. While the taint analysis reported no issues, this may be due to the limited attack surface or scope of the analysis.
The plugin's vulnerability history is clean, with no recorded CVEs. This suggests a history of responsible development or that the plugin has not been a significant target for public vulnerability discovery. Despite the lack of historical vulnerabilities, the identified output escaping issues require immediate attention to prevent potential exploitation and ensure a secure user experience. The strengths in SQL handling and limited attack surface are positive, but the XSS risk is a significant weakness.
Key Concerns
- All identified outputs are unescaped
- No nonce checks implemented
- No capability checks implemented
PowerFM Radyo Security Vulnerabilities
PowerFM Radyo Code Analysis
Output Escaping
PowerFM Radyo Attack Surface
Maintenance & Trust
PowerFM Radyo Maintenance & Trust
Maintenance Signals
Community Trust
PowerFM Radyo Alternatives
Rock & Pop Radio
rock-pop-radio
We aim to caress your auditory receptors, bringing you to a harmonized climax, leaving you wanting more. Allow us to pound your ears with our energeti …
Audioburst Podcast Highlights Player
audioburst-player-widget
Add short-form talk-audio to your blog or website. Highlight your own podcast or enrich blog post with bursts of relevant short-form audio content.
Now playing for AzuraCast
now-playing-widget-fuer-azuracast-stationen
Display currently played song of an AzuraCast instance in a sidebar.
Radiojar Audio Player
radiojar-player
Audio player plugin for Radiojar platform , just by dragging the widget or added shortcode [rj-player].
Codescar Radio Widget
codescar-radio-widget
Codescar Radio Widget produces a widget allowing users listen to a radio station from your website.
PowerFM Radyo Developer Profile
1 plugin · 10 total installs
How We Detect PowerFM Radyo
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
<img src="http://radyo.gen.tr/gorsel/power-fm-dinle_400x400_17.jpg" width=300px alt="Powerfm"><audio controls loop><source src="http://powerfm.listenpowerapp.com/powerfm/mpeg/icecast.audio" />Lütfen Bekleyiniz.</audio>