
tf Song List Security & Risk Analysis
wordpress.org/plugins/tf-song-listtf Song List is an easy-to-use song listing plugin for bands and solo musicians.
Is tf Song List Safe to Use in 2026?
Generally Safe
Score 85/100tf Song List has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The tf-song-list v1.1.0 plugin demonstrates a generally good security posture with several positive indicators. Notably, all SQL queries are prepared, and there are no identified critical or high severity taint flows. The absence of any recorded vulnerabilities, including critical or high severity ones, is a strong positive signal regarding its historical security. The presence of nonce and capability checks, along with no external HTTP requests, further contributes to its security. However, a significant concern arises from the output escaping, where only 25% of outputs are properly escaped. This suggests a risk of Cross-Site Scripting (XSS) vulnerabilities, particularly given that the plugin has one shortcode, which is a common vector for such attacks. While the attack surface is small and appears to have no direct unprotected entry points, the low rate of proper output escaping warrants attention.
Key Concerns
- Low percentage of properly escaped output
tf Song List Security Vulnerabilities
tf Song List Release Timeline
tf Song List Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
tf Song List Attack Surface
Shortcodes 1
WordPress Hooks 9
Maintenance & Trust
tf Song List Maintenance & Trust
Maintenance Signals
Community Trust
tf Song List Alternatives
Bandsintown Events
bandsintown
Bandsintown's Events plugin for displaying your upcoming events.
Simple Popup Plugin
simple-popup-plugin
This plugin makes it easy to create a simple, modifiable popup window.
Transcoder
transcoder
Transcoding services for ANY WordPress website. Convert audio/video files of any format to a web-friendly format (mp3/mp4).
WP Chords
wp-chords
WP Chords allows you to format and display the chords on your blog including mobile friendly interface and AMP functionality.
Better Bandsintown
better-bandsintown
Embed Tour Dates from Bandsintown.com without having to deal with CSS (or an ugly widget).
tf Song List Developer Profile
8 plugins · 2K total installs
How We Detect tf Song List
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tf-song-list/css/tf-song-list.css/wp-content/plugins/tf-song-list/js/tf-song-list.js/wp-content/plugins/tf-song-list/js/tf-song-list.jstf-song-list/css/tf-song-list.css?ver=tf-song-list/js/tf-song-list.js?ver=HTML / DOM Fingerprints
tf_song_list_wrappertf_song_list_tabletf_song_list_headertf_song_list_rowtf_song_list_celltf_song_list_options[tf_song_list]