
Stream Player by netmix® – Streaming audio for WordPress! Security & Risk Analysis
wordpress.org/plugins/stream-playerFree, open source streaming audio player plugin by netmix®. Works with Icecast, Shoutcast, and Live 365 streams. For additional features, upgrade to S …
Is Stream Player by netmix® – Streaming audio for WordPress! Safe to Use in 2026?
Generally Safe
Score 100/100Stream Player by netmix® – Streaming audio for WordPress! has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'stream-player' plugin v2.5.16 exhibits a mixed security posture. On the positive side, it demonstrates good practices by ensuring all output is properly escaped and has no known historical vulnerabilities. The plugin also utilizes nonce checks and capability checks, which are essential for securing WordPress functionalities. However, a significant concern arises from its attack surface, particularly the presence of 9 AJAX handlers with 6 of them lacking proper authentication checks. This represents a considerable risk as unauthenticated AJAX actions can be exploited by attackers to perform unauthorized operations. Additionally, the taint analysis revealed 4 flows with unsanitized paths, though none were classified as critical or high severity, this still indicates potential for vulnerabilities if not addressed, especially in conjunction with the unprotected AJAX endpoints.
The plugin's vulnerability history is a strong positive, with no recorded CVEs. This suggests a generally stable and well-maintained codebase. However, the static analysis findings, specifically the unprotected AJAX endpoints and unsanitized paths, cannot be ignored. The absence of vulnerabilities in the past might be due to a lack of targeted discovery or a fortunate lack of exploitation, rather than a guaranteed secure state. Therefore, while the plugin has strengths in output escaping and historical security, the identified attack surface concerns necessitate careful consideration for potential exploitation.
Key Concerns
- Unprotected AJAX handlers
- Flows with unsanitized paths
Stream Player by netmix® – Streaming audio for WordPress! Security Vulnerabilities
Stream Player by netmix® – Streaming audio for WordPress! Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Stream Player by netmix® – Streaming audio for WordPress! Attack Surface
AJAX Handlers 9
Shortcodes 2
WordPress Hooks 36
Maintenance & Trust
Stream Player by netmix® – Streaming audio for WordPress! Maintenance & Trust
Maintenance Signals
Community Trust
Stream Player by netmix® – Streaming audio for WordPress! Alternatives
Radio Station by netmix® – Manage and play your Show Schedule in WordPress!
radio-station
Radio Station lets you build and manage a Show Schedule for a radio station or Internet broadcaster's WordPress website.
StreamCast – Live Radio Streaming Player
streamcast
StreamCast allows you to play IceCast, Shoutcast, Radionomy, RadioJar, RadioCo and more beautifully inside WordPress.
Radio Player Page
radio-player-page
Dedicated player pages for your radio streams, with program scheduling and continuous playback.
Simple Radio Forty Two
simple-radio-forty-two
Écoutez votre radio préférée directement depuis WordPress avec Simple Radio Forty Two.
AnowRadio Player
anowradio-player
Embed radio player widget on your WordPress site using API key.
Stream Player by netmix® – Streaming audio for WordPress! Developer Profile
3 plugins · 1K total installs
How We Detect Stream Player by netmix® – Streaming audio for WordPress!
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/stream-player/css/admin.css/wp-content/plugins/stream-player/css/player.css/wp-content/plugins/stream-player/css/styles.css/wp-content/plugins/stream-player/js/admin.js/wp-content/plugins/stream-player/js/player.js/wp-content/plugins/stream-player/js/scripts.js/wp-content/plugins/stream-player/js/player.js/wp-content/plugins/stream-player/js/admin.jsstream-player/css/admin.css?ver=stream-player/css/player.css?ver=stream-player/css/styles.css?ver=stream-player/js/admin.js?ver=stream-player/js/player.js?ver=stream-player/js/scripts.js?ver=HTML / DOM Fingerprints
sp-player-containersp-playlist-container<!-- Stream Player --><!-- /Stream Player -->data-sp-iddata-sp-autoplaydata-sp-loopdata-sp-volumeStreamPlayerStreamPlayerAdmin/wp-json/stream-player/v1/settings[stream-player[/stream-player]