
Sheet Music Libary Security & Risk Analysis
wordpress.org/plugins/sheet-music-libraryThe sheet music library plugin is a framework that leverages WordPress to post sheet music online in a structured way. Using a sheet music custom post …
Is Sheet Music Libary Safe to Use in 2026?
Generally Safe
Score 92/100Sheet Music Libary has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The sheet-music-library plugin version 2.0.1 exhibits a mixed security posture. On the positive side, it has no recorded vulnerabilities or CVEs, suggesting a history of responsible development and patching. The code analysis also shows a lack of dangerous functions, no file operations, and no external HTTP requests, which are good security indicators. However, there are significant concerns, primarily stemming from its attack surface and output escaping practices. A notable portion of outputs are not properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities, especially if user-supplied data is involved in rendering.
The most critical finding is the presence of an AJAX handler without any authentication checks. This creates a direct entry point for unauthenticated users to potentially interact with plugin functionality in unintended ways, posing a significant security risk. While the plugin utilizes prepared statements for its SQL queries, the lack of capability checks on the unprotected AJAX handler is a more immediate and severe threat. The absence of common vulnerability types in its history is encouraging, but it doesn't negate the risks identified in the current code analysis. Overall, while the plugin has some good security foundations, the unprotected AJAX endpoint and the poor output escaping practices introduce substantial vulnerabilities that require immediate attention.
Key Concerns
- AJAX handler without auth checks
- Low percentage of properly escaped output
- No capability checks found
Sheet Music Libary Security Vulnerabilities
Sheet Music Libary Code Analysis
Output Escaping
Data Flow Analysis
Sheet Music Libary Attack Surface
AJAX Handlers 1
Shortcodes 3
WordPress Hooks 19
Maintenance & Trust
Sheet Music Libary Maintenance & Trust
Maintenance Signals
Community Trust
Sheet Music Libary Alternatives
EMP Song Selector Tool for Mobile DJs
emp-song-selector
Allows DJs to upload their song list from a CSV file so that customers can search/select songs for their party. Also creates PDF file of song list.
OpenSheetMusicDisplay
opensheetmusicdisplay
Block or shortcode to render MusicXML in the browser as sheet music using OSMD.
FileBird – WordPress Media Library Folders & File Manager
filebird
Organize thousands of WordPress media files in folders / categories with ease.
Instant Images – One-click Image Uploads from Unsplash, Openverse, Pixabay, Pexels, and Giphy
instant-images
One-click uploads from Unsplash, Openverse, Pixabay, Pexels, and Giphy directly to your WordPress media library.
Real Media Library: Media Library Folder & File Manager
real-media-library-lite
Organize uploaded media in folders, collections and galleries: A file manager for WordPress. Media management made easy with Real Media Library! (Alte …
Sheet Music Libary Developer Profile
27 plugins · 24K total installs
How We Detect Sheet Music Libary
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sheet-music-library/template/sheet-music-library.css/wp-content/plugins/sheet-music-library/admin/sheet-music-admin.css/wp-content/plugins/sheet-music-library/admin/sheet-music-admin.jsHTML / DOM Fingerprints
sml-piece-detailssml-attachment-wrapsml-attachment-previewsml-attachment-infosml-field-labelsml-file-inputdata-score-attachment-iddata-parts-attachment-iddata-audio-attachment-iddata-video-urldata-no-downloaddata-piece-info+4 moresheetMusicOptions[all_sheet_music][latest_sheet_music][sheet_music_audio_playlist]