
Radiopotok Security & Risk Analysis
wordpress.org/plugins/radiopotokЭтот виджет предоставляет вам возможность прослушивать онлайн радиостанции выбранные на сайте http://radiopotok.ru/radio_on_site
Is Radiopotok Safe to Use in 2026?
Generally Safe
Score 85/100Radiopotok has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "radiopotok" plugin v0.1 exhibits a generally good security posture based on the provided static analysis. It demonstrates a lack of dangerous functions, no file operations, and no external HTTP requests, which are positive indicators. Crucially, all identified SQL queries utilize prepared statements, and there are no recorded vulnerabilities or CVEs associated with this plugin, suggesting a history of secure development or limited prior exposure. The presence of a capability check, even with a limited attack surface, is a positive sign of some security awareness.
However, a significant concern arises from the output escaping. With 10 total outputs analyzed, only 20% are properly escaped. This indicates a high potential for cross-site scripting (XSS) vulnerabilities, where user-supplied data, if not properly sanitized, could be injected into the output and executed by a user's browser. While the attack surface is currently reported as zero, this could change with future updates. The absence of nonce checks on AJAX handlers and REST API routes is also a weakness, although currently mitigated by the zero count of these entry points. It's essential to address the output escaping issues proactively to prevent future security breaches.
In conclusion, "radiopotok" v0.1 has strengths in its avoidance of common pitfalls like raw SQL and external requests, and a clean vulnerability history. Nevertheless, the poor output escaping is a critical weakness that needs immediate attention. Addressing this, along with implementing proper nonce checks should these entry points become active, will significantly improve the plugin's overall security.
Key Concerns
- Poor output escaping (80% unescaped)
Radiopotok Security Vulnerabilities
Radiopotok Code Analysis
Output Escaping
Data Flow Analysis
Radiopotok Attack Surface
WordPress Hooks 8
Maintenance & Trust
Radiopotok Maintenance & Trust
Maintenance Signals
Community Trust
Radiopotok Alternatives
Radiopotok Developer Profile
1 plugin · 10 total installs
How We Detect Radiopotok
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/radiopotok/admin.phphttp://radiopotok.ru/f/script4/HTML / DOM Fingerprints
RPv4-wellRPv4-well-smallRPv4-radioplayer-wrapperRPv4-radioplayerRPv4-btn-groupRPv4-btnRPv4-dropdown-toggleRPv4-caret+1 moreid="RP_v4_radio"class="RPv4-well RPv4-well-small"class="RPv4-radioplayer-wrapper"id="RP_v4_radioplayer"class="RPv4-btn-group" align="left"class="RPv4-btn RPv4-dropdown-toggle"+3 moreRP_v4_theme<div id="RP_v4_radio" align="center" class="RPv4-well RPv4-well-small"><div class="RPv4-radioplayer-wrapper"><div id="RP_v4_radioplayer"></div></div><div class="RPv4-btn-group" align="left"><a class="RPv4-btn RPv4-dropdown-toggle" data-toggle="dropdown" href="http://radiopotok.ru/">Онлайн радио<span class="RPv4-caret"></span></a><ul class="RPv4-dropdown-menu"></ul></div></div>