Tradecast Security & Risk Analysis

wordpress.org/plugins/tradecast

Connect your Tradecast channel to your WordPress website easily, using the official Tradecast plugin for WordPress.

0 active installs v1.0.1 PHP 7.1+ WP + Updated May 5, 2022
platformtradecastvideo
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Tradecast Safe to Use in 2026?

Generally Safe

Score 85/100

Tradecast has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The 'tradecast' v1.0.1 plugin exhibits a strong security posture based on the static analysis results. The absence of any identified vulnerabilities in its history is a positive indicator. Furthermore, the code demonstrates good practices by having zero dangerous functions, 100% of SQL queries utilizing prepared statements, and all identified output being properly escaped. The plugin also avoids common pitfalls like file operations, suggesting a limited potential for file inclusion or manipulation vulnerabilities. However, a few areas warrant attention. The presence of an external HTTP request without further context is a potential concern. While the attack surface appears minimal with zero entry points, the absence of nonce checks and capability checks on any potential, albeit currently unrevealed, interaction points is a significant gap. The lack of recorded vulnerability history might also be a double-edged sword, as it could indicate either a well-developed plugin or a lack of thorough historical auditing.

Key Concerns

  • External HTTP request without context
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Tradecast Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Tradecast Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
19 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

100% escaped19 total outputs
Attack Surface

Tradecast Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 13
actionplugins_loadedincludes\class-tradecast.php:72
actionadmin_enqueue_scriptsincludes\class-tradecast.php:84
actionadmin_menuincludes\class-tradecast.php:90
actioninitincludes\class-tradecast.php:93
actionrest_api_initincludes\class-tradecast.php:99
actionrest_api_initincludes\class-tradecast.php:106
actionrest_api_initincludes\class-tradecast.php:113
filterparent_fileincludes\class-tradecast.php:129
actionwp_enqueue_scriptsincludes\class-tradecast.php:147
actioninitincludes\class-tradecast.php:150
actioninitincludes\class-tradecast.php:156
actioninitincludes\class-tradecast.php:162
actioninitincludes\class-tradecast.php:163
Maintenance & Trust

Tradecast Maintenance & Trust

Maintenance Signals

WordPress version tested5.9.13
Last updatedMay 5, 2022
PHP min version7.1
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Tradecast Developer Profile

Tradecast BV

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Tradecast

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/tradecast/admin/assets/tradecast-admin.css/wp-content/plugins/tradecast/admin/assets/tradecast-admin.umd.min.js
Script Paths
/wp-content/plugins/tradecast/admin/assets/tradecast-admin.umd.min.js
Version Parameters
tradecast-admin?ver=1.0.0tradecast-admin?ver=1.0.1

HTML / DOM Fingerprints

JS Globals
tradecastWpAdminSettings
REST Endpoints
/wp-json/tradecast/v1/video/wp-json/tradecast/v1/gallery/wp-json/tradecast/v1/settings
FAQ

Frequently Asked Questions about Tradecast