
Plugin Name: Spotify Play Button for WordPress Security & Risk Analysis
wordpress.org/plugins/spotify-play-for-wordpressEasily embed Spotify Tracks & Playslists using the Spotify Play System into your WordPress Blog
Is Plugin Name: Spotify Play Button for WordPress Safe to Use in 2026?
Generally Safe
Score 85/100Plugin Name: Spotify Play Button for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'spotify-play-for-wordpress' plugin v0.2.1 exhibits a mixed security posture. On the positive side, it demonstrates a commitment to secure coding practices by not utilizing dangerous functions, all SQL queries are prepared, and there are no recorded vulnerabilities in its history. This suggests a generally well-maintained and secure codebase to date. However, the static analysis reveals some areas for concern. The plugin has a very low percentage of properly escaped output (13%), which is a significant weakness. While the attack surface is small, the lack of nonce checks on the single shortcode, which is an entry point, represents a potential risk for cross-site request forgery (CSRF) or other injection attacks if user-supplied data is not handled with extreme care within the shortcode's logic. The absence of taint analysis flows is noted, but this may be due to the limited nature of the analysis or the plugin's functionality. Overall, the plugin is relatively secure due to its lack of known vulnerabilities and use of prepared statements, but the poor output escaping and the potential for unmitigated shortcode entry points warrant attention.
Key Concerns
- Low percentage of properly escaped output
- Shortcode entry point without nonce check
Plugin Name: Spotify Play Button for WordPress Security Vulnerabilities
Plugin Name: Spotify Play Button for WordPress Code Analysis
Output Escaping
Plugin Name: Spotify Play Button for WordPress Attack Surface
Shortcodes 1
WordPress Hooks 7
Maintenance & Trust
Plugin Name: Spotify Play Button for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
Plugin Name: Spotify Play Button for WordPress Alternatives
Liza Widget For Spotify and Elementor
liza-spotify-widget-for-elementor
Spotify Widget, Spotify, Easy to use Spotify widget.
Sp*tify Play Button for WordPress
spotify-play-button-for-wordpress
Now with Gutenberg block!
Spotiembed
spotiembed
A simple plugin which adds an Elementor widget to usable widget library. The plugin enables option to use dynamic URL in builders.
Privacy Embed
privacy-embed
Providing shortcodes to privacy-friendly embed external elements (like YouTube videos).
Classic Widgets
classic-widgets
Enables the previous "classic" widgets settings screens in Appearance - Widgets and the Customizer. Disables the block editor from managing widgets.
Plugin Name: Spotify Play Button for WordPress Developer Profile
13 plugins · 7K total installs
How We Detect Plugin Name: Spotify Play Button for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.