
Sermons-NL Security & Risk Analysis
wordpress.org/plugins/sermons-nlThe plugin nicely presents church services and broadcasting data from Kerktijden.nl, Kerkomroep.nl and Youtube.com, frequently used by Dutch churches.
Is Sermons-NL Safe to Use in 2026?
Generally Safe
Score 100/100Sermons-NL has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The sermons-nl v1.3 plugin demonstrates a generally positive security posture with several good practices in place. The absence of known CVEs and a history of unpatched vulnerabilities suggests a commitment to security or a lack of past discoveries. The code analysis shows a relatively low percentage of SQL queries that do not use prepared statements, and a good proportion of output being properly escaped, mitigating common web vulnerabilities. Furthermore, the lack of file operations and external HTTP requests reduces the attack surface in those areas.
However, there are areas of concern that warrant attention. The plugin exposes 15 total entry points, with a notable 4 AJAX handlers lacking authentication checks. This is a significant risk as it could allow unauthenticated users to trigger potentially sensitive actions. While no critical taint flows were detected, the presence of unprotected AJAX endpoints could be exploited to lead to other vulnerabilities if not properly secured. The plugin also has a moderate number of external HTTP requests (4), which, while not flagged as an issue here, can sometimes introduce supply chain risks if the external services are compromised.
In conclusion, sermons-nl v1.3 is a reasonably secure plugin due to its good handling of SQL and output escaping, and its clean vulnerability history. The primary weakness lies in the unprotected AJAX endpoints, which represent a direct and exploitable security risk. Addressing these unprotected entry points should be the immediate priority to further strengthen the plugin's security.
Key Concerns
- AJAX handlers without auth checks
Sermons-NL Security Vulnerabilities
Sermons-NL Code Analysis
SQL Query Safety
Output Escaping
Sermons-NL Attack Surface
AJAX Handlers 12
Shortcodes 3
WordPress Hooks 7
Scheduled Events 2
Maintenance & Trust
Sermons-NL Maintenance & Trust
Maintenance Signals
Community Trust
Sermons-NL Alternatives
EmbedPress – PDF Embedder, Embed YouTube Videos, 3D FlipBook, Social feeds, Docs & more
embedpress
EmbedPress lets you embed videos, pages, social feeds, embed PDF 3D flipbooks & other content on WordPress without coding & enhance storytelling.
Feeds for YouTube (YouTube video, channel, and gallery plugin)
feeds-for-youtube
The Feeds for YouTube plugin allows you to display customizable YouTube feeds from any YouTube channel.
The Ultimate Video Player For WordPress – by Presto Player
presto-player
The Ultimate WordPress Video Player.
Embed Plus for YouTube Gallery, Livestream and Lazy Loading with Facades
youtube-embed-plus
A multi-featured plugin to embed YouTube in WordPress. Embed a video, YouTube channel gallery, playlist, or YouTube livestream. Defer JavaScript too!
iframe
iframe
[iframe src="http://www.youtube.com/embed/7_nAZQt9qu0" width="100%" height="500"] shortcode
Sermons-NL Developer Profile
1 plugin · 0 total installs
How We Detect Sermons-NL
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sermons-nl/js/sermons-nl-admin-settings.js/wp-content/plugins/sermons-nl/js/sermons-nl-frontend.js/wp-content/plugins/sermons-nl/css/sermons-nl-admin-settings.css/wp-content/plugins/sermons-nl/css/sermons-nl-frontend.css/wp-content/plugins/sermons-nl/js/sermons-nl-admin-settings.js/wp-content/plugins/sermons-nl/js/sermons-nl-frontend.jssermons-nl/js/sermons-nl-admin-settings.js?ver=sermons-nl/js/sermons-nl-frontend.js?ver=sermons-nl/css/sermons-nl-admin-settings.css?ver=sermons-nl/css/sermons-nl-frontend.css?ver=HTML / DOM Fingerprints
sermons-nl-admin-settings-pagesermons-nl-frontend-container<!-- sermons-nl: start shortcode --><!-- sermons-nl: end shortcode --><!-- Sermons-NL invalid shortcode -->data-sermons-nl-event-iddata-sermons-nl-audio-urldata-sermons-nl-video-urlsermons_nl_ajax_object[sermons-nl][sermons_nl]