
Song Book Security & Risk Analysis
wordpress.org/plugins/song-bookAdd worship songbooks to your site
Is Song Book Safe to Use in 2026?
Generally Safe
Score 92/100Song Book has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "song-book" v1.3 plugin exhibits a generally strong security posture based on the static analysis. A key strength is the absence of identified entry points such as AJAX handlers, REST API routes, shortcodes, or cron events that lack authentication checks. Furthermore, the code signals indicate a good implementation of security measures like nonce checks and capability checks, with a significant percentage of output properly escaped, and no dangerous functions or file operations detected. The lack of vulnerability history, including CVEs, further supports a positive security assessment.
However, the analysis does reveal a potential concern within the SQL query handling. With one SQL query identified and 0% of them using prepared statements, this presents a significant risk of SQL injection vulnerabilities. This is particularly concerning as it's the only identified database interaction and is not protected by proper sanitization. The taint analysis showing zero flows with unsanitized paths is a positive sign, but it doesn't negate the risk posed by the raw SQL query.
In conclusion, while the plugin demonstrates excellent practice in limiting its attack surface and implementing many security checks, the sole SQL query's lack of prepared statements is a critical weakness that needs immediate attention. Addressing this single SQL vulnerability would significantly improve the plugin's overall security.
Key Concerns
- SQL queries not using prepared statements
Song Book Security Vulnerabilities
Song Book Code Analysis
SQL Query Safety
Output Escaping
Song Book Attack Surface
WordPress Hooks 61
Maintenance & Trust
Song Book Maintenance & Trust
Maintenance Signals
Community Trust
Song Book Alternatives
Church Content – Sermons, Events and More
church-theme-content
Provides an interface for managing sermons, events, people and locations. A compatible theme is required for presenting content from these church-cent …
Visual Bible Verse of the Day Widget
visual-verse-of-the-day-widget
Six days a week a new photo and scripture reference will appear from The Visual Bible Verse of the Day at visualverse.thecreationspeaks.com.
sermon.net display
display-sermonnet
A plugin that brings in your sermon.net data (sermon audio, sermon video, pdf, and live stream) for display on your WordPress website.
BibleUp
bibleup
BibleUp transforms Bible references on a webpage into links and makes the text accessible via a flexible and highly-customizable popover.
WP-Bible Embed
wp-bible-embed
There are many wordpress Bible plugins, but none of them embed the whole entire Bible... Except this one.
Song Book Developer Profile
5 plugins · 290 total installs
How We Detect Song Book
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/song-book/assets/css/icons.csssong-book/assets/css/icons.css?ver=