
StreamCast – Live Radio Streaming Player Security & Risk Analysis
wordpress.org/plugins/streamcastStreamCast allows you to play IceCast, Shoutcast, Radionomy, RadioJar, RadioCo and more beautifully inside WordPress.
Is StreamCast – Live Radio Streaming Player Safe to Use in 2026?
Generally Safe
Score 99/100StreamCast – Live Radio Streaming Player has a strong security track record. Known vulnerabilities have been patched promptly.
The "streamcast" v2.3.9 plugin exhibits a generally good security posture based on the static analysis. The absence of unprotected entry points, dangerous functions, raw SQL queries, and external HTTP requests are positive indicators. Taint analysis revealing no unsanitized paths further strengthens this view. However, the plugin's history of two medium-severity Cross-Site Scripting (XSS) vulnerabilities, with the last one being quite recent (August 2024), raises a significant concern. While there are currently no unpatched CVEs, this pattern suggests a recurring weakness in input sanitization or output escaping, which could be exploited in future versions if not thoroughly addressed. The plugin correctly implements nonce and capability checks for its AJAX handlers and shortcodes, and all SQL queries utilize prepared statements. The 70% output escaping rate is a moderate weakness, as the remaining 30% of outputs could potentially be vulnerable to XSS if they handle user-supplied data without proper escaping. The Freemius library version is also noted, though its specific version is not an immediate red flag without further context on its known vulnerabilities.
Key Concerns
- Recent Medium Severity XSS Vulnerabilities
- 30% of Outputs Not Properly Escaped
- Bundled Library Freemius v1.0
StreamCast – Live Radio Streaming Player Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
StreamCast <= 2.2.3 - Authenticated (Editor+) Stored Cross-Site Scripting
StreamCast – Radio Player for WordPress <= 2.1.0 - Cross-Site Scripting
StreamCast – Live Radio Streaming Player Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
StreamCast – Live Radio Streaming Player Attack Surface
AJAX Handlers 5
Shortcodes 2
WordPress Hooks 66
Maintenance & Trust
StreamCast – Live Radio Streaming Player Maintenance & Trust
Maintenance Signals
Community Trust
StreamCast – Live Radio Streaming Player Alternatives
Shoutcast Icecast HTML5 Radio Player
shoutcast-icecast-html5-radio-player
A secure HTML5 radio player for Shoutcast, Icecast, and podcast streams with social sharing.
FWD Plasmic Audio Player
fwd-plasmic-audio-player
Powerful and extremely customizable 3D audio player with an organic sphere visualizer, playlist support, and Shoutcast/Icecast playback.
WPRadio – WordPress Radio Streaming Plugin
wpradio
An entire radio streaming platform within your WordPress site.
Radio Player Page
radio-player-page
Dedicated player pages for your radio streams, with program scheduling and continuous playback.
Serverless Radio
serverless-radio
A serverless MP3 linear streaming plugin that lets you create AutoDJ-like playlists from public MP3 folders — no VPS required.
StreamCast – Live Radio Streaming Player Developer Profile
120 plugins · 738K total installs
How We Detect StreamCast – Live Radio Streaming Player
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/streamcast/assets/css/backend.min.css/wp-content/plugins/streamcast/assets/css/frontend.min.css/wp-content/plugins/streamcast/assets/js/backend.min.js/wp-content/plugins/streamcast/assets/js/frontend.min.js/wp-content/plugins/streamcast/vendor/freemius/start.phpstreamcast/assets/css/backend.min.css?ver=streamcast/assets/css/frontend.min.css?ver=streamcast/assets/js/backend.min.js?ver=streamcast/assets/js/frontend.min.js?ver=HTML / DOM Fingerprints
streamcast_playerdata-streamcast-iddata-streamcast-typestreamcast_config[streamcast