WebSpeechAPI for WP Security & Risk Analysis

wordpress.org/plugins/webspeechapi-for-wp

This is voice input plugin using Web Speech API Web Speech APIを使用した音声入力プラグインです。

40 active installs v1.1 PHP + WP 4.8+ Updated Apr 17, 2018
voice-inputvoice-recognitionwebspeechapi
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WebSpeechAPI for WP Safe to Use in 2026?

Generally Safe

Score 85/100

WebSpeechAPI for WP has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the webspeechapi-for-wp plugin v1.1 exhibits a strong security posture. The static analysis reveals no identifiable entry points such as AJAX handlers, REST API routes, or shortcodes that could be directly exploited. Furthermore, there are no detected dangerous functions, raw SQL queries, unescaped output, or file operations. The absence of external HTTP requests and the lack of non-trivial code signals like nonce or capability checks is also noteworthy, suggesting a minimal and well-contained codebase.

The taint analysis also shows no identified flows with unsanitized paths, indicating that data processed by the plugin is likely handled securely. The vulnerability history is equally positive, with zero recorded CVEs of any severity. This indicates a lack of publicly known or previously discovered security weaknesses in this plugin, which is a significant strength.

While the absence of explicit security checks like nonce and capability checks might seem like a weakness in isolation, in the context of a zero attack surface and zero taint flows, it suggests that the plugin's functionality is either extremely limited or that its integration points are handled externally. The overall impression is one of a secure and well-developed plugin, with no immediate threats or concerns stemming from the analyzed data.

Vulnerabilities
None known

WebSpeechAPI for WP Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WebSpeechAPI for WP Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

WebSpeechAPI for WP Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_enqueue_scriptswebspeechapi.php:18
actionadmin_enqueue_scriptswebspeechapi.php:23
actionedit_form_after_titlewebspeechapi.php:41
Maintenance & Trust

WebSpeechAPI for WP Maintenance & Trust

Maintenance Signals

WordPress version tested4.8.28
Last updatedApr 17, 2018
PHP min version
Downloads12K

Community Trust

Rating0/100
Number of ratings0
Active installs40
Developer Profile

WebSpeechAPI for WP Developer Profile

Yu Onoda

1 plugin · 40 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WebSpeechAPI for WP

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/webspeechapi-for-wp/js/webspeechapi.js/wp-content/plugins/webspeechapi-for-wp/css/style.css
Script Paths
/wp-content/plugins/webspeechapi-for-wp/js/webspeechapi.js
Version Parameters
webspeechapi-for-wp/js/webspeechapi.js?ver=webspeechapi-for-wp/css/style.css?ver=

HTML / DOM Fingerprints

CSS Classes
wsapiwp_bodywsapiwp_content_leftwsapiwp_content_rightwsapiwp_content_btns
Data Attributes
id="progress"id="status"id="speech_start"id="speech_stop"
JS Globals
wsapiwp_function
Shortcode Output
<div class="wsapiwp_body clearfix"><div class="wsapiwp_content_left"><h2>Interim sentence:</h2><span id="progress" cols="" rows="3"></span>
FAQ

Frequently Asked Questions about WebSpeechAPI for WP