
Radio Station by netmix® – Manage and play your Show Schedule in WordPress! Security & Risk Analysis
wordpress.org/plugins/radio-stationRadio Station lets you build and manage a Show Schedule for a radio station or Internet broadcaster's WordPress website.
Is Radio Station by netmix® – Manage and play your Show Schedule in WordPress! Safe to Use in 2026?
Generally Safe
Score 97/100Radio Station by netmix® – Manage and play your Show Schedule in WordPress! has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "radio-station" v2.5.17 plugin exhibits a mixed security posture. While it demonstrates strong adherence to best practices in SQL query preparation (94% prepared) and output escaping (98% escaped), a significant concern arises from its attack surface. A substantial number of AJAX handlers (21 out of 31) lack authentication checks, presenting a wide gateway for unauthorized actions if exploited. Furthermore, the taint analysis reveals 29 flows with unsanitized paths, including 4 identified as high severity. This, combined with a history of 3 medium-severity CVEs, including Cross-Site Request Forgery and Cross-Site Scripting, suggests a recurring pattern of vulnerabilities that, if left unaddressed, could lead to serious compromises. The plugin also bundles the Freemius library v1.0, which might be outdated and present its own set of risks. Overall, the plugin has strong foundations in secure coding for common web vulnerabilities, but the lack of robust authentication on numerous entry points and the presence of high-severity unsanitized paths are significant weaknesses that require immediate attention.
Key Concerns
- Unprotected AJAX handlers
- High severity unsanitized taint flows
- Bundled outdated library (Freemius v1.0)
- Medium severity CVE history
Radio Station by netmix® – Manage and play your Show Schedule in WordPress! Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Radio Station <= 2.5.12 - Cross-Site Request Forgery
Radio Station by netmix® – Manage and play your Show Schedule in WordPress! <= 2.5.7 - Cross-Site Request Forgery to Notice Dismissal
Radio Station <= 2.4.0.9 - Reflected Cross-Site Scripting
Radio Station by netmix® – Manage and play your Show Schedule in WordPress! Release Timeline
Radio Station by netmix® – Manage and play your Show Schedule in WordPress! Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Radio Station by netmix® – Manage and play your Show Schedule in WordPress! Attack Surface
AJAX Handlers 31
Shortcodes 31
WordPress Hooks 200
Maintenance & Trust
Radio Station by netmix® – Manage and play your Show Schedule in WordPress! Maintenance & Trust
Maintenance Signals
Community Trust
Radio Station by netmix® – Manage and play your Show Schedule in WordPress! Alternatives
Quran Radio
quran-radio
Quran Radio plugin is the first WordPress plugin that allows you to add a widget that plays an online Radio station for the translation of the Quran.
Radio Player Page
radio-player-page
Dedicated player pages for your radio streams, with program scheduling and continuous playback.
Codescar Radio Widget
codescar-radio-widget
Codescar Radio Widget produces a widget allowing users listen to a radio station from your website.
Radio Station by netmix® – Manage and play your Show Schedule in WordPress! Developer Profile
3 plugins · 1K total installs
How We Detect Radio Station by netmix® – Manage and play your Show Schedule in WordPress!
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/radio-station/admin/css/settings.css/wp-content/plugins/radio-station/admin/css/jquery-ui.min.css/wp-content/plugins/radio-station/admin/js/settings.js/wp-content/plugins/radio-station/admin/js/jquery-ui.min.js/wp-content/plugins/radio-station/assets/css/style.css/wp-content/plugins/radio-station/assets/js/radio.js/wp-content/plugins/radio-station/assets/js/player.js/wp-content/plugins/radio-station/assets/js/players/html5.js+2 more/wp-content/plugins/radio-station/admin/js/settings.js/wp-content/plugins/radio-station/admin/js/jquery-ui.min.js/wp-content/plugins/radio-station/assets/js/radio.js/wp-content/plugins/radio-station/assets/js/player.js/wp-content/plugins/radio-station/assets/js/players/html5.js/wp-content/plugins/radio-station/assets/js/players/youtube.js+1 moreradio-station/admin/css/settings.css?ver=radio-station/admin/css/jquery-ui.min.css?ver=radio-station/admin/js/settings.js?ver=radio-station/admin/js/jquery-ui.min.js?ver=radio-station/assets/css/style.css?ver=radio-station/assets/js/radio.js?ver=radio-station/assets/js/player.js?ver=radio-station/assets/js/players/html5.js?ver=radio-station/assets/js/players/youtube.js?ver=radio-station/assets/js/players/soundcloud.js?ver=HTML / DOM Fingerprints
radio-station-settingsradio-station-playerradio-station-containerradio-station-player-html5radio-station-player-youtuberadio-station-player-soundcloud<!-- Radio Station Player --><!-- Radio Station Settings -->data-radio-station-iddata-radio-station-player-typeradioStation/wp-json/radio-station/v1/player/wp-json/radio-station/v1/settings[radio-station-player][radio-station-playlist]