
Radio VERA Security & Risk Analysis
wordpress.org/plugins/radio-veraThis widget displays player radio VERA, Russian-language only.
Is Radio VERA Safe to Use in 2026?
Generally Safe
Score 85/100Radio VERA has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "radio-vera" plugin v2.2 exhibits a generally good security posture with no recorded vulnerabilities or known CVEs. The static analysis shows a remarkably small attack surface with no identified entry points like AJAX handlers, REST API routes, or shortcodes that lack authentication or permission checks. Furthermore, all SQL queries are properly prepared, indicating a strength in database interaction security.
However, there are significant concerns. The presence of `create_function`, a deprecated and potentially insecure PHP function, is a clear red flag. While not currently exploited in the analyzed code, it can be a vector for remote code execution if user input is ever passed to it without strict sanitization. The very low percentage of properly escaped output (5%) is also a major weakness, making the plugin highly susceptible to Cross-Site Scripting (XSS) vulnerabilities. The lack of nonce and capability checks across the board, though not directly exploitable due to the zero attack surface, represents a significant gap in fundamental WordPress security practices that could become problematic if the attack surface expands in future versions.
In conclusion, while the plugin currently benefits from a zero-known-vulnerability status and a contained attack surface, the identified code signals of `create_function` and critically low output escaping present tangible risks. The absence of basic security checks like nonces and capability checks suggests a lack of robust security development practices. Future development should prioritize sanitizing all output and removing the use of `create_function`.
Key Concerns
- Use of create_function
- Very low output escaping (5%)
- No nonce checks
- No capability checks
Radio VERA Security Vulnerabilities
Radio VERA Code Analysis
Dangerous Functions Found
Output Escaping
Radio VERA Attack Surface
WordPress Hooks 2
Maintenance & Trust
Radio VERA Maintenance & Trust
Maintenance Signals
Community Trust
Radio VERA Alternatives
WPC Variations Radio Buttons for WooCommerce
wpc-variations-radio-buttons
WPC Variations Radio Buttons will replace dropdown select with radio buttons for the buyer easier in selecting the variations.
Select All Categories and Taxonomies, Change Checkbox to Radio Buttons
select-all-categories-and-taxonomies-change-checkbox-to-radio-buttons
Use radio buttons or checkboxes for your categories and custom taxonomies with this incredibly powerful and easy-to-use plugin.
WC Variations Radio Buttons
wc-variations-radio-buttons
Variations Radio Buttons for WooCommerce. Let your customers choose product variations using radio buttons instead of dropdowns.
Shipping Method Display Style for WooCommerce
woo-shipping-display-mode
This plugin provides a configuration to display shipping methods as Radio button or select box on the checkout page.
Meks Audio Player
meks-audio-player
Easily enhance your podcast, music or any audio files with a full-featured and customizable sticky audio player.
Radio VERA Developer Profile
3 plugins · 80 total installs
How We Detect Radio VERA
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/radio-vera/circle.skin/circle.player.css/wp-content/plugins/radio-vera/js/jquery.js/wp-content/plugins/radio-vera/js/jquery.jplayer.min.js/wp-content/plugins/radio-vera/js/jquery.transform2d.js/wp-content/plugins/radio-vera/js/jquery.grab.js/wp-content/plugins/radio-vera/js/mod.csstransforms.min.js/wp-content/plugins/radio-vera/js/jquery.cookie.js/wp-content/plugins/radio-vera/js/circle.player.js+5 more/wp-content/plugins/radio-vera/js/jquery.js/wp-content/plugins/radio-vera/js/jquery.jplayer.min.js/wp-content/plugins/radio-vera/js/jquery.transform2d.js/wp-content/plugins/radio-vera/js/jquery.grab.js/wp-content/plugins/radio-vera/js/mod.csstransforms.min.js/wp-content/plugins/radio-vera/js/jquery.cookie.js+2 moreHTML / DOM Fingerprints
cp-jplayercp-containercp-buffer-holdercp-buffer-1cp-buffer-2cp-progress-holdercp-progress-1cp-progress-2+4 more//<![CDATA[//// http://radiovera.hostingradio.ru:8007/radiovera_128//+2 moreid="radio-vera-player"id="jquery_jplayer_radiovera"class="cp-jplayer"id="cp_container_1"class="cp-container"class="cp-buffer-holder"+11 morewindow.jQuerymyCirclePlayerCirclePlayer