Spreaker Shortcode Security & Risk Analysis

wordpress.org/plugins/spreaker-shortcode

A simple and easy way to embed Spreaker player into your WordPress blog.

4K active installs v1.8.3 PHP + WP 2.5.0+ Updated Sep 16, 2024
audioembedshortcodespreakerwidget
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Spreaker Shortcode Safe to Use in 2026?

Generally Safe

Score 92/100

Spreaker Shortcode has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "spreaker-shortcode" plugin v1.8.3 presents a generally strong security posture based on the provided static analysis. The absence of dangerous functions, SQL queries executed via prepared statements, properly escaped output, and no file operations or external HTTP requests are all positive indicators. Furthermore, the plugin has no recorded vulnerabilities, CVEs, or a history of past issues, which suggests a well-maintained codebase. The limited attack surface, consisting only of two shortcodes with no identified unprotected entry points, further contributes to its good security standing.

Despite the positive findings, there are a few areas that warrant attention. The absence of nonce checks and capability checks on its entry points (shortcodes) represents a potential weakness. While the static analysis did not identify any specific taint flows or exploitable vulnerabilities in this version, this lack of validation means that if a vulnerability were introduced in the future, it could be more easily exploited, especially if the shortcode processing itself has any subtle flaws. The fact that there are zero recorded vulnerabilities in its history is excellent, but it's important to remain vigilant, as past security performance does not guarantee future immunity.

In conclusion, "spreaker-shortcode" v1.8.3 is a secure plugin with robust coding practices. The primary concern lies in the lack of explicit nonce and capability checks for its shortcodes. While no immediate risks are evident in this version's analysis, implementing these checks would significantly strengthen its defenses against potential future threats and ensure a more comprehensive security approach.

Key Concerns

  • Missing nonce checks on shortcodes
  • Missing capability checks on shortcodes
Vulnerabilities
None known

Spreaker Shortcode Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Spreaker Shortcode Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
6 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped6 total outputs
Attack Surface

Spreaker Shortcode Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[spreaker] spreaker_shortcode.php:190
[spreaker] trunk\spreaker_shortcode.php:190
Maintenance & Trust

Spreaker Shortcode Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedSep 16, 2024
PHP min version
Downloads98K

Community Trust

Rating66/100
Number of ratings9
Active installs4K
Developer Profile

Spreaker Shortcode Developer Profile

Spreaker

1 plugin · 4K total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Spreaker Shortcode

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/spreaker-shortcode/css/spreaker-shortcode.css
Version Parameters
spreaker-shortcode/css/spreaker-shortcode.css?ver=

HTML / DOM Fingerprints

Shortcode Output
<iframe src="https://widget.spreaker.com/player? frameborder="0"></iframe>
FAQ

Frequently Asked Questions about Spreaker Shortcode