
Sermon Manager Import Security & Risk Analysis
wordpress.org/plugins/sermon-manager-importImports sermons into Sermon Manager using ID3 information.
Is Sermon Manager Import Safe to Use in 2026?
Generally Safe
Score 85/100Sermon Manager Import has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The sermon-manager-import plugin v0.2.5 exhibits a generally positive security posture based on the provided static analysis and vulnerability history. The absence of dangerous functions, the exclusive use of prepared statements for SQL queries, and the lack of external HTTP requests are strong indicators of good development practices. Furthermore, the plugin has no recorded vulnerabilities or CVEs, suggesting a history of security-conscious maintenance or a lack of targeted exploitation. However, there are areas for improvement. The fact that 41% of output is not properly escaped presents a potential Cross-Site Scripting (XSS) risk, especially if the plugin handles user-provided input that is later displayed. The complete absence of nonce checks and capability checks for its entry points (shortcodes in this case) is a significant concern, as it implies that any authenticated user could potentially trigger the plugin's functionality without proper authorization or protection against CSRF attacks. While the attack surface is small and currently unprotected entry points are zero, the lack of specific security checks for the existing shortcodes opens up a vulnerability window. In conclusion, while the plugin is free from known critical vulnerabilities and demonstrates good SQL hygiene, the unescaped output and the lack of nonces/capability checks on shortcodes are significant weaknesses that warrant attention.
Key Concerns
- Significant portion of output not properly escaped
- No nonce checks on entry points (shortcodes)
- No capability checks on entry points (shortcodes)
Sermon Manager Import Security Vulnerabilities
Sermon Manager Import Code Analysis
SQL Query Safety
Output Escaping
Sermon Manager Import Attack Surface
Shortcodes 2
WordPress Hooks 34
Maintenance & Trust
Sermon Manager Import Maintenance & Trust
Maintenance Signals
Community Trust
Sermon Manager Import Alternatives
Podcast Searcher by Clarify
podcast-searcher-by-clarify
The Clarify plugin allows you to make any audio or video embedded in your posts, pages, etc searchable via the standard WordPress search box.
Liteweight Podcast – Host and Embed Podcast Episodes
liteweight-podcast
A lite weight Podcasting plugin for WordPress which contain lots of options and functionality to run your podcasting website.
La Tecnologeria Podcasting players
la-tecnologeria-podcasting-players
A plugin to add external players easily in your web using shortcodes.
AudioTracks
audiotracks
Manage a directory of audio tracks in WordPress.
Remove Query Arg from Media URLs ?_=1
remove-query-arg-from-media
Remove the query string ?_=1 added by WordPress adds to media URLs in HTML5 audio and video mediaelement.js players.
Sermon Manager Import Developer Profile
1 plugin · 90 total installs
How We Detect Sermon Manager Import
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sermon-manager-import/css/sermon-manager-import.css/wp-content/plugins/sermon-manager-import/js/sermon-manager-import.js/wp-content/plugins/sermon-manager-import/js/sermon-manager-import.jssermon-manager-import/css/sermon-manager-import.css?ver=sermon-manager-import/js/sermon-manager-import.js?ver=HTML / DOM Fingerprints
sermon-manager-import-optionsdata-plugin-slug="sermon-manager-import"