
Stratus Security & Risk Analysis
wordpress.org/plugins/stratusStratus is a jQuery powered SoundCloud player that lives at the bottom (or top) of your website or blog.
Is Stratus Safe to Use in 2026?
Generally Safe
Score 85/100Stratus has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "stratus" v1.0.0 plugin exhibits a strong initial security posture, as indicated by the absence of any identified vulnerabilities in its history and a clean static analysis report regarding dangerous functions, SQL queries, file operations, and external HTTP requests. The plugin also reports zero AJAX handlers, REST API routes, shortcodes, or cron events, leading to a minimal attack surface with no immediately apparent unprotected entry points. This suggests a thoughtful approach to development regarding common security pitfalls.
However, the analysis does highlight a significant concern with output escaping. With one total output and 0% properly escaped, there is a high risk of cross-site scripting (XSS) vulnerabilities. Any data rendered to the user interface without proper sanitization or escaping can be exploited by attackers to inject malicious scripts. The lack of nonce checks and capability checks, while not inherently a problem given the zero entry points, means that if any entry points were to be introduced in future versions, they would lack critical authorization and security controls.
Given the plugin's version (1.0.0) and the absence of known vulnerabilities, it's plausible that this is a new or very well-maintained plugin. The clean history is a positive indicator, but the unescaped output is a critical flaw that needs immediate attention to prevent potential exploitation. The overall assessment is that while the plugin has a solid foundation, the output escaping issue presents a tangible and severe risk that undermines its otherwise good security practices.
Key Concerns
- Unescaped output detected
Stratus Security Vulnerabilities
Stratus Release Timeline
Stratus Code Analysis
Output Escaping
Stratus Attack Surface
WordPress Hooks 4
Maintenance & Trust
Stratus Maintenance & Trust
Maintenance Signals
Community Trust
Stratus Alternatives
Player for SoundCloud – Embed and Play Audio Tracks
embed-soundcloud-block
SoundCloud is the new music network on the block that allows users to create, record and share sounds and music with family, friends and the world.
ToneDen Player Shortcode
toneden-player-shortcode
Enables shortcode to embed ToneDen's new SoundCloud player in WordPress blogs.
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar
mp3-music-player-by-sonaar
The most advanced Audio Player for Music & Podcast. For Elementor, Gutenberg, WooCommerce and more. Add unlimited players to any pages!
Music Player for Elementor – Audio Player & Podcast Player
music-player-for-elementor
Audio Player for Elementor – the go-to plugin for adding MP3s, podcasts & playlists. Fully customizable, WooCommerce-ready, and mobile-friendly.
mb.miniAudioPlayer – an HTML5 audio player for your mp3 files
wp-miniaudioplayer
Transform your mp3 audio files into a nice, small light HTML5 player.
Stratus Developer Profile
1 plugin · 30 total installs
How We Detect Stratus
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/stratus/stratus.jshttp://stratus.sc/stratus.jsHTML / DOM Fingerprints
window.jQuery.stratus