Radiopotok Security & Risk Analysis

wordpress.org/plugins/radiopotok

Этот виджет предоставляет вам возможность прослушивать онлайн радиостанции выбранные на сайте http://radiopotok.ru/radio_on_site

10 active installs v0.1 PHP + WP 3.0.1+ Updated Jan 20, 2013
online-radio
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Radiopotok Safe to Use in 2026?

Generally Safe

Score 85/100

Radiopotok has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 13yr ago
Risk Assessment

The "radiopotok" plugin v0.1 exhibits a generally good security posture based on the provided static analysis. It demonstrates a lack of dangerous functions, no file operations, and no external HTTP requests, which are positive indicators. Crucially, all identified SQL queries utilize prepared statements, and there are no recorded vulnerabilities or CVEs associated with this plugin, suggesting a history of secure development or limited prior exposure. The presence of a capability check, even with a limited attack surface, is a positive sign of some security awareness.

However, a significant concern arises from the output escaping. With 10 total outputs analyzed, only 20% are properly escaped. This indicates a high potential for cross-site scripting (XSS) vulnerabilities, where user-supplied data, if not properly sanitized, could be injected into the output and executed by a user's browser. While the attack surface is currently reported as zero, this could change with future updates. The absence of nonce checks on AJAX handlers and REST API routes is also a weakness, although currently mitigated by the zero count of these entry points. It's essential to address the output escaping issues proactively to prevent future security breaches.

In conclusion, "radiopotok" v0.1 has strengths in its avoidance of common pitfalls like raw SQL and external requests, and a clean vulnerability history. Nevertheless, the poor output escaping is a critical weakness that needs immediate attention. Addressing this, along with implementing proper nonce checks should these entry points become active, will significantly improve the plugin's overall security.

Key Concerns

  • Poor output escaping (80% unescaped)
Vulnerabilities
None known

Radiopotok Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Radiopotok Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
2 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

20% escaped10 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
radiopotok_conf (admin.php:41)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Radiopotok Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionadmin_menuadmin.php:2
actionadmin_noticesadmin.php:16
actionadmin_initadmin.php:21
filterplugin_action_linksadmin.php:39
actionjetpack_admin_menuadmin.php:80
actionwp_headradiopotok.php:85
actioninitradiopotok.php:86
actionwidgets_initradiopotok.php:87
Maintenance & Trust

Radiopotok Maintenance & Trust

Maintenance Signals

WordPress version tested3.5.2
Last updatedJan 20, 2013
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Radiopotok Developer Profile

radiopotok

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Radiopotok

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/radiopotok/admin.php
Script Paths
http://radiopotok.ru/f/script4/

HTML / DOM Fingerprints

CSS Classes
RPv4-wellRPv4-well-smallRPv4-radioplayer-wrapperRPv4-radioplayerRPv4-btn-groupRPv4-btnRPv4-dropdown-toggleRPv4-caret+1 more
Data Attributes
id="RP_v4_radio"class="RPv4-well RPv4-well-small"class="RPv4-radioplayer-wrapper"id="RP_v4_radioplayer"class="RPv4-btn-group" align="left"class="RPv4-btn RPv4-dropdown-toggle"+3 more
JS Globals
RP_v4_theme
Shortcode Output
<div id="RP_v4_radio" align="center" class="RPv4-well RPv4-well-small"><div class="RPv4-radioplayer-wrapper"><div id="RP_v4_radioplayer"></div></div><div class="RPv4-btn-group" align="left"><a class="RPv4-btn RPv4-dropdown-toggle" data-toggle="dropdown" href="http://radiopotok.ru/">Онлайн радио<span class="RPv4-caret"></span></a><ul class="RPv4-dropdown-menu"></ul></div></div>
FAQ

Frequently Asked Questions about Radiopotok