PowerPress GetID3 1.9.3 add-on Security & Risk Analysis

wordpress.org/plugins/powerpress-getid3

Replaces the GetID3 library used in PowerPress with an older version 1.9.3.

10 active installs v1.0.1 PHP + WP 4.4+ Updated Mar 15, 2020
getid3powerpress
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is PowerPress GetID3 1.9.3 add-on Safe to Use in 2026?

Generally Safe

Score 85/100

PowerPress GetID3 1.9.3 add-on has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The powerpress-getid3 plugin, version 1.0.1, exhibits a strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points indicates a minimal attack surface. Furthermore, the code signals reveal excellent security practices, including 100% of SQL queries using prepared statements and a very high percentage of properly escaped output. The lack of dangerous functions and external HTTP requests also contributes positively to its security profile.

The vulnerability history is also clean, with no recorded CVEs or common vulnerability types. This suggests a well-maintained and secure codebase over time, or at least a lack of publicly disclosed vulnerabilities. The taint analysis showing zero flows with unsanitized paths reinforces the impression of a secure implementation.

Overall, this plugin appears to be very secure. The primary potential area for concern, though not directly identified as a flaw in this analysis, is the lack of any explicit capability or nonce checks on the entry points. While there are no entry points identified in this analysis, if any were to be introduced in future versions without proper checks, it could create vulnerabilities. However, based solely on the provided data, the plugin demonstrates a commendable commitment to security best practices.

Key Concerns

  • No capability checks detected
  • No nonce checks detected
Vulnerabilities
None known

PowerPress GetID3 1.9.3 add-on Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

PowerPress GetID3 1.9.3 add-on Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
30 escaped
Nonce Checks
0
Capability Checks
0
File Operations
69
External Requests
0
Bundled Libraries
0

Output Escaping

97% escaped31 total outputs
Attack Surface

PowerPress GetID3 1.9.3 add-on Attack Surface

Entry Points0
Unprotected0
Maintenance & Trust

PowerPress GetID3 1.9.3 add-on Maintenance & Trust

Maintenance Signals

WordPress version tested5.4.19
Last updatedMar 15, 2020
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

PowerPress GetID3 1.9.3 add-on Developer Profile

Angelo Mandato

7 plugins · 10K total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect PowerPress GetID3 1.9.3 add-on

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/powerpress-getid3/getid3-1.9.3/getid3.php/wp-content/plugins/powerpress-getid3/getid3-1.9.3/module.audio.mp3.php/wp-content/plugins/powerpress-getid3/getid3-1.9.3/module.audio-video.quicktime.php
Version Parameters
powerpress-getid3/getid3-1.9.3/getid3.php?ver=powerpress-getid3/getid3-1.9.3/module.audio.mp3.php?ver=powerpress-getid3/getid3-1.9.3/module.audio-video.quicktime.php?ver=

HTML / DOM Fingerprints

JS Globals
GETID3_INCLUDEPATH
FAQ

Frequently Asked Questions about PowerPress GetID3 1.9.3 add-on