
Sp*tify Play Button for WordPress Security & Risk Analysis
wordpress.org/plugins/spotify-play-button-for-wordpressNow with Gutenberg block!
Is Sp*tify Play Button for WordPress Safe to Use in 2026?
Generally Safe
Score 89/100Sp*tify Play Button for WordPress has a strong security track record. Known vulnerabilities have been patched promptly.
The spotify-play-button-for-wordpress plugin, version 2.13, presents a mixed security profile. On the positive side, the static analysis reveals a minimal attack surface with only one shortcode and no unprotected entry points. The code demonstrates good practices by using prepared statements for all SQL queries and implementing a nonce check. Furthermore, the absence of dangerous functions, file operations, external HTTP requests, and taint flows with unsanitized paths is commendable. However, the plugin's history is a significant concern, with a total of four known medium-severity CVEs, all of which are currently patched. The common vulnerability types, Cross-Site Request Forgery (CSRF) and Cross-site Scripting (XSS), suggest potential issues with how user input is handled and validated, even though current static analysis did not flag unsanitized outputs. The fact that all past vulnerabilities have been medium-severity suggests a pattern of exploitable flaws that, while not critical, can still pose a risk if not promptly patched.
Key Concerns
- Past medium severity CVEs indicate potential for XSS/CSRF
- One output not properly escaped
- No capability checks on shortcode
Sp*tify Play Button for WordPress Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
Spotify Play Button for WordPress <= 2.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via spotifyplaybutton Shortcode
Sp*tify Play Button for WordPress <= 2.10 - Cross-Site Request Forgery
Sp*tify Play Button for WordPress <= 2.07 - Authenticated (Administrator+) Stored Cross-Site Scripting
Sp*tify Play Button for WordPress <= 2.05 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Sp*tify Play Button for WordPress Code Analysis
Output Escaping
Data Flow Analysis
Sp*tify Play Button for WordPress Attack Surface
Shortcodes 1
WordPress Hooks 6
Maintenance & Trust
Sp*tify Play Button for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
Sp*tify Play Button for WordPress Alternatives
PowerPress Podcasting plugin by Blubrry
powerpress
No. 1 Podcasting plugin for WordPress.
Podcast Subscribe Buttons
podcast-subscribe-buttons
Add beautiful podcast subscribe buttons anywhere.
Anchor Episodes Index (Spotify for Podcasters)
anchor-episodes-index
A lightweight plugin that allows you to output an anchor.fm podcast player on your site that includes an episode index. Just add two URL's on the …
Liza Widget For Spotify and Elementor
liza-spotify-widget-for-elementor
Spotify Widget, Spotify, Easy to use Spotify widget.
TechGasp Music Master
spotify-master
TechGasp Music Master allows you to display in your wordpress website musics, playlists and albums of the cool and "booming" music network Spotify.
Sp*tify Play Button for WordPress Developer Profile
10 plugins · 14K total installs
How We Detect Sp*tify Play Button for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/spotify-play-button-for-wordpress/sptify-play-button-for-wordpress-icon.pngHTML / DOM Fingerprints
my_shortcode_addspotifyplaybutton_tinymce_popup_buttonspotifyplaybutton_tinymce_popup_insert_buttonid="spotifyplaybutton_tinymce_popup_playlist"id="spotifyplaybutton_tinymce_popup_insert_button"<iframe style="max-height:src="https://open.spotify.com/embed/?utm_source=generatorframeBorder="0" allowfullscreen="" allow="autoplay; clipboard-write; encrypted-media; fullscreen; picture-in-picture" loading="lazy"></iframe>