Rabbit Lyrics Security & Risk Analysis

wordpress.org/plugins/rabbit-lyrics

JavaScript audio and timed lyrics synchronizer.

10 active installs v0.1.0 PHP 7.0.0+ WP 5.6.0+ Updated Mar 12, 2021
audioaudio-booksblocklyricsmusic
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Rabbit Lyrics Safe to Use in 2026?

Generally Safe

Score 85/100

Rabbit Lyrics has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "rabbit-lyrics" plugin v0.1.0 demonstrates an exceptionally strong security posture based on the provided static analysis. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, resulting in a zero attack surface with no unprotected entry points. The code itself adheres to best practices, with no dangerous functions, all SQL queries utilizing prepared statements, and 100% of output properly escaped. Furthermore, there are no file operations, external HTTP requests, or recorded vulnerability history (CVEs). This indicates a plugin that has been developed with security as a primary consideration and has likely undergone thorough internal testing. The absence of any taint analysis findings reinforces the conclusion that no sensitive data flows are being mishandled within the analyzed code.

While the current analysis presents a nearly flawless security profile, it's important to acknowledge that this is a snapshot based on static analysis of version 0.1.0. The plugin is at a very early stage (0.1.0), which often means its functionality is limited and thus the attack surface is naturally small. As the plugin evolves and adds features, new entry points and potential vulnerabilities could be introduced. The complete lack of nonce checks and capability checks, while not a direct issue in this version due to the absence of entry points, could become a significant concern if any such entry points are added in future updates without proper security measures. The plugin's strength lies in its current minimalism and adherence to core secure coding principles.

Vulnerabilities
None known

Rabbit Lyrics Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Rabbit Lyrics Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Rabbit Lyrics Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actioninitrabbit-lyrics.php:101
Maintenance & Trust

Rabbit Lyrics Maintenance & Trust

Maintenance Signals

WordPress version tested5.6.0
Last updatedMar 12, 2021
PHP min version7.0.0
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Rabbit Lyrics Developer Profile

guoyunhe

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Rabbit Lyrics

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/rabbit-lyrics/build/index.js/wp-content/plugins/rabbit-lyrics/build/index.css/wp-content/plugins/rabbit-lyrics/build/script.js/wp-content/plugins/rabbit-lyrics/build/style-index.css
Script Paths
/wp-content/plugins/rabbit-lyrics/build/index.js/wp-content/plugins/rabbit-lyrics/build/script.js
Version Parameters
rabbit-lyrics/build/index.js?ver=rabbit-lyrics/build/index.css?ver=rabbit-lyrics/build/script.js?ver=rabbit-lyrics/build/style-index.css?ver=rabbit-lyrics/themes/twentytwenty.css?ver=rabbit-lyrics/themes/twentytwentyone.css?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Rabbit Lyrics