
Last.FM Recent Tracks – WordPress Plugin Security & Risk Analysis
wordpress.org/plugins/recent-tracks-lastfmWith this plugin you can add your recent scrobbled tracks on Last.FM to your site.
Is Last.FM Recent Tracks – WordPress Plugin Safe to Use in 2026?
Generally Safe
Score 85/100Last.FM Recent Tracks – WordPress Plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "recent-tracks-lastfm" v1.1 plugin exhibits a generally low risk profile based on the provided static analysis. It has a very small attack surface, with only one shortcode, and importantly, no identified AJAX handlers or REST API routes that are unprotected. The code also demonstrates good practices regarding SQL queries, with 100% using prepared statements, and no critical or high-severity taint flows were detected.
However, there are significant areas of concern that temper the overall positive assessment. The most glaring issue is that 0% of output is properly escaped, meaning any data rendered by the plugin could be vulnerable to cross-site scripting (XSS) attacks. Furthermore, the plugin lacks any nonce checks or capability checks, which are crucial for verifying user intent and permissions, especially for shortcodes which can be rendered on public-facing pages.
With no recorded vulnerabilities in its history, the plugin appears to have been stable in the past. Nevertheless, the presence of unescaped output and the absence of essential security checks represent tangible, exploitable risks that could be leveraged by attackers. While the plugin has strengths in its limited attack surface and secure SQL practices, the critical lack of output escaping and authorization controls warrants caution.
Key Concerns
- 0% output escaping
- 0 nonce checks
- 0 capability checks
Last.FM Recent Tracks – WordPress Plugin Security Vulnerabilities
Last.FM Recent Tracks – WordPress Plugin Code Analysis
Output Escaping
Last.FM Recent Tracks – WordPress Plugin Attack Surface
Shortcodes 1
WordPress Hooks 2
Maintenance & Trust
Last.FM Recent Tracks – WordPress Plugin Maintenance & Trust
Maintenance Signals
Community Trust
Last.FM Recent Tracks – WordPress Plugin Alternatives
Trancelantic Playlist
trancelantic-playlist
Trancelantic Playlist is a cool plugin that is able to display your currently played song on your website through a widget.
Last.fm Recent Plays – WordPress Plugin
lastfm-recent-plays-wordpress-plugin
With this simple plugin you can easily add your most recent scrobbles on Last.fm to your WordPress website.
Last.fm RPS
lastfm-rps
Widget Plugin that lists your recently listened songs on your sidebar with album or artist images and text.
Transcoder
transcoder
Transcoding services for ANY WordPress website. Convert audio/video files of any format to a web-friendly format (mp3/mp4).
WP Chords
wp-chords
WP Chords allows you to format and display the chords on your blog including mobile friendly interface and AMP functionality.
Last.FM Recent Tracks – WordPress Plugin Developer Profile
1 plugin · 10 total installs
How We Detect Last.FM Recent Tracks – WordPress Plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/recent-tracks-lastfm/lastfm-style.cssHTML / DOM Fingerprints
recent-trackstrack-itemtrack-albumtrack-artisttrack-nametrack-description<ul class="recent-tracks"><li class="track-item"><a href="<img src="