Radiojar Audio Player Security & Risk Analysis

wordpress.org/plugins/radiojar-player

Audio player plugin for Radiojar platform , just by dragging the widget or added shortcode [rj-player].

100 active installs v1.4 PHP 5.6.33+ WP 4.8+ Updated Jun 10, 2020
audio-playermp3-playermusic-playerradiojarwidget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Radiojar Audio Player Safe to Use in 2026?

Generally Safe

Score 85/100

Radiojar Audio Player has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The radiojar-player plugin v1.4 exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, SQL injection vulnerabilities, file operations, and external HTTP requests is commendable. The use of prepared statements for all SQL queries further enhances its security.

However, there are areas for improvement. A significant portion of output is not properly escaped (56%), which could lead to cross-site scripting (XSS) vulnerabilities if untrusted data is directly rendered. The lack of nonce checks and capability checks for the identified entry points (shortcodes) is a concern, as it suggests that these functionalities might be exploitable by unauthenticated or unauthorized users, potentially leading to unintended actions or information disclosure.

The plugin's vulnerability history is clean, with no recorded CVEs. This suggests a good track record, but it's crucial to remember that a clean history does not guarantee future security. The current analysis reveals potential weaknesses in output sanitization and authentication/authorization mechanisms for its entry points, which should be addressed to maintain this secure standing.

Key Concerns

  • Unescaped output detected (44%)
  • Missing nonce checks on entry points
  • Missing capability checks on entry points
Vulnerabilities
None known

Radiojar Audio Player Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Radiojar Audio Player Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
14
18 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

56% escaped32 total outputs
Attack Surface

Radiojar Audio Player Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[rj-player] inc\admin-settings.php:365
[rj-chat] inc\admin-settings.php:455
WordPress Hooks 7
actionadmin_menuinc\admin-settings.php:235
actionadmin_initinc\admin-settings.php:242
actionadmin_enqueue_scriptsinc\admin-settings.php:249
actionadmin_footerinc\admin-settings.php:300
filterwidget_textinc\admin-settings.php:397
actionwp_enqueue_scriptsinc\admin-settings.php:451
actionwidgets_initinc\widget.php:29
Maintenance & Trust

Radiojar Audio Player Maintenance & Trust

Maintenance Signals

WordPress version tested5.4.19
Last updatedJun 10, 2020
PHP min version5.6.33
Downloads7K

Community Trust

Rating100/100
Number of ratings1
Active installs100
Developer Profile

Radiojar Audio Player Developer Profile

Radiojar

1 plugin · 100 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Radiojar Audio Player

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/radiojar-player/images/poweredby.png/wp-content/plugins/radiojar-player/images/player1.png/wp-content/plugins/radiojar-player/images/player2.png/wp-content/plugins/radiojar-player/images/player3.png
Script Paths
//proxy.radiojar.com/wrappers/api-plugins/v2/radiojar-min.js

HTML / DOM Fingerprints

CSS Classes
wrapform-tableradiojar-player
Data Attributes
name="rjplayer_settings[station_id]"name="rjplayer_settings[autoplay]"name="rjplayer_settings[player]"name="rjplayer_settings[default_image]"name="rjplayer_settings[chat_width]"name="rjplayer_settings[chat_height]"+1 more
JS Globals
rjq
Shortcode Output
[rj-player]
FAQ

Frequently Asked Questions about Radiojar Audio Player