
Serverless Radio Security & Risk Analysis
wordpress.org/plugins/serverless-radioA serverless MP3 linear streaming plugin that lets you create AutoDJ-like playlists from public MP3 folders — no VPS required.
Is Serverless Radio Safe to Use in 2026?
Generally Safe
Score 100/100Serverless Radio has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "serverless-radio" plugin v0.9.0 exhibits several concerning security practices, despite a clean vulnerability history. The primary issue lies in its attack surface, with two AJAX handlers exposed without any authentication or capability checks. This means any unauthenticated user could potentially trigger these handlers, leading to unintended actions or information disclosure if they are not robustly secured internally.
The static analysis reveals two taint flows with unsanitized paths, which, while not classified as critical or high severity in this specific analysis, indicate a potential risk for cross-site scripting (XSS) or other injection vulnerabilities if these paths are not handled with extreme care. The plugin also shows a low rate of properly escaped output (47%), which significantly increases the risk of XSS vulnerabilities. The absence of nonce checks on AJAX handlers further compounds this risk, as it allows for cross-site request forgery (CSRF) attacks.
While the plugin has no recorded vulnerabilities, this lack of history should not be mistaken for inherent security. It may simply reflect a lack of rigorous security auditing or exploitation of less obvious vulnerabilities. The plugin does demonstrate good practices by using prepared statements for all SQL queries. However, the presence of unprotected entry points, unsanitized taint flows, and a high percentage of unescaped output are significant weaknesses that overshadow the positive aspects, warranting careful consideration and immediate remediation.
Key Concerns
- Unprotected AJAX handlers
- Flows with unsanitized paths
- Low percentage of properly escaped output
- Missing nonce checks on AJAX handlers
- No capability checks on AJAX handlers
Serverless Radio Security Vulnerabilities
Serverless Radio Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Serverless Radio Attack Surface
AJAX Handlers 2
WordPress Hooks 6
Maintenance & Trust
Serverless Radio Maintenance & Trust
Maintenance Signals
Community Trust
Serverless Radio Alternatives
Compact WP Audio Player
compact-wp-audio-player
A Compact WP Audio Player Plugin that is compatible with all major browsers and devices (Android, iPhone, iPad)
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar
mp3-music-player-by-sonaar
The most advanced Audio Player for Music & Podcast. For Elementor, Gutenberg, WooCommerce and more. Add unlimited players to any pages!
AudioIgniter Music Player
audioigniter
AudioIgniter lets you create music playlists and embed them in your WordPress posts, pages or custom post types and serve your audio content in style!
HTML5 Audio Player – The Ultimate No-Code Podcast, MP3 & Audio Player
html5-audio-player
Maximize your WordPress site's potential with our versatile HTML5 Audio Player plugin. Seamlessly play .mp3, .wav, .ogg, and more audio files.
Music Player for Elementor – Audio Player & Podcast Player
music-player-for-elementor
Audio Player for Elementor – the go-to plugin for adding MP3s, podcasts & playlists. Fully customizable, WooCommerce-ready, and mobile-friendly.
Serverless Radio Developer Profile
9 plugins · 1K total installs
How We Detect Serverless Radio
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/serverless-radio/player/images/dd.png/wp-content/plugins/serverless-radio/player/images/preloaderResult.gifHTML / DOM Fingerprints
grabfaarrowsid="arrayorder_0"id="title0"id="song0"id="duration0"id="arrayorder_1"id="title1"+11 morevar slrvar idno/wp-json/serverless-radio<iframe src="?slr=