Spinitron Player Security & Risk Analysis

wordpress.org/plugins/spinitron-player

A streaming player for radio stations using Spinitron, with live data integration.

20 active installs v1.0.9 PHP 7.2+ WP 5.2+ Updated Dec 9, 2025
musicplayerradiospinitronstream
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Spinitron Player Safe to Use in 2026?

Generally Safe

Score 100/100

Spinitron Player has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The spinitron-player plugin version 1.0.9 exhibits a generally positive security posture with some notable exceptions. The plugin demonstrates good practices by utilizing prepared statements for all SQL queries and ensuring nearly all output is properly escaped. The absence of known vulnerabilities and critical taint flows further contributes to a favorable security outlook. However, the presence of two AJAX handlers without authentication checks represents a significant concern, creating potential entry points for unauthorized actions.

The limited attack surface, combined with strong practices in data handling and output sanitization, suggests a well-developed plugin. The external HTTP request, while present, is likely for legitimate plugin functionality and without further context or associated vulnerabilities, poses a low immediate risk. The vulnerability history being clear of any recorded CVEs is a strong indicator of historical security diligence. Despite these strengths, the unprotected AJAX endpoints necessitate careful consideration.

In conclusion, spinitron-player 1.0.9 has many security strengths, particularly in its database interaction and output handling. The lack of known vulnerabilities is also highly encouraging. The primary weakness lies in the unprotected AJAX handlers, which should be addressed to fully secure the plugin. Overall, it's a plugin with a good foundation but requires a minor refinement to eliminate potential security gaps.

Key Concerns

  • AJAX handlers without authentication
  • No nonce checks on AJAX handlers
Vulnerabilities
None known

Spinitron Player Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Spinitron Player Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
86 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

99% escaped87 total outputs
Attack Surface
2 unprotected

Spinitron Player Attack Surface

Entry Points4
Unprotected2

AJAX Handlers 2

authwp_ajax_fetch_spinitron_show_todayajax\ajax-handler-today.php:125
noprivwp_ajax_fetch_spinitron_show_todayajax\ajax-handler-today.php:126

Shortcodes 2

[spinitron_player] spinitron-player.php:66
[spinitron_play_button] spinitron-player.php:172
WordPress Hooks 4
actionadmin_initapp\plugin-settings.php:90
actionadmin_menuapp\plugin-settings.php:155
actionadmin_enqueue_scriptsapp\plugin-settings.php:215
actionwp_enqueue_scriptsspinitron-player.php:38
Maintenance & Trust

Spinitron Player Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 9, 2025
PHP min version7.2
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs20
Developer Profile

Spinitron Player Developer Profile

Razorfrog Web Design

4 plugins · 420 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Spinitron Player

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/spinitron-player/style.css/wp-content/plugins/spinitron-player/js/spinitron-fetch-today.js
Script Paths
/wp-content/plugins/spinitron-player/js/spinitron-fetch-today.js
Version Parameters
spinitron-player/style.css?ver=1.0.5spinitron-player/js/spinitron-fetch-today.js?ver=1.0.5

HTML / DOM Fingerprints

CSS Classes
spinitron-stream-buttonspinitron-stream-button-text
HTML Comments
<!-- Button markup kept IDENTICAL to your original -->
Data Attributes
data-spinitron-show-iddata-spinitron-stream-url
JS Globals
spinitron_paramsSpinitronSharedAudio
Shortcode Output
[spinitron_player][spinitron_play_button]
FAQ

Frequently Asked Questions about Spinitron Player