Spotify Follow Widget Security & Risk Analysis

wordpress.org/plugins/spotify-follow-button-widget

A wordpress plugin allowing you to add spotify follow buttons as widgets on the sites

40 active installs v1.0 PHP + WP 3.0.1+ Updated Jan 11, 2014
musicspotifywidget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Spotify Follow Widget Safe to Use in 2026?

Generally Safe

Score 85/100

Spotify Follow Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12yr ago
Risk Assessment

The Spotify Follow Button Widget plugin version 1.0 exhibits a generally strong security posture based on the provided static analysis. The plugin has no recorded vulnerabilities (CVEs), which is a significant positive indicator. Furthermore, the static analysis reveals no dangerous functions, no raw SQL queries, no file operations, and no external HTTP requests, all of which contribute to a reduced attack surface. However, there are notable concerns. The plugin has a very low percentage of properly escaped output (10%), indicating a high likelihood of Cross-Site Scripting (XSS) vulnerabilities. Additionally, the absence of nonce checks and capability checks on potential entry points, coupled with zero found entry points in the initial scan, raises questions about the robustness of its security controls if new entry points were introduced or discovered. The lack of taint analysis results also makes it difficult to fully assess the risk of data manipulation.

Key Concerns

  • Low percentage of properly escaped output
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Spotify Follow Widget Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Spotify Follow Widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
19
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

10% escaped21 total outputs
Attack Surface

Spotify Follow Widget Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionwidgets_initspotify-follow.php:125
Maintenance & Trust

Spotify Follow Widget Maintenance & Trust

Maintenance Signals

WordPress version tested3.4.2
Last updatedJan 11, 2014
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs40
Developer Profile

Spotify Follow Widget Developer Profile

drsounds

1 plugin · 40 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Spotify Follow Widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

Data Attributes
widget_spotify_uriwidget_themewidget_size
Shortcode Output
<iframe src="https://embed.spotify.com/follow/1/?size=&uri=&theme=" width="300" height="56" scrolling="no" frameborder="0" style="border:none; overflow:hidden;" allowtransparency="true"></iframe>
FAQ

Frequently Asked Questions about Spotify Follow Widget