3Q Video Connect Security & Risk Analysis

wordpress.org/plugins/3q-video-connect

3Q-SDN integration plugin. Add your 3Q-SDN Videos and Livestreams to your Wordpress Blogs or Pages. Upload new VoD videos to your 3Q-SDN Account.

10 active installs v1.0.0 PHP 5.2.4+ WP 4.2+ Updated Mar 25, 2020
3qlivestreamsdnvideovideos
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is 3Q Video Connect Safe to Use in 2026?

Generally Safe

Score 85/100

3Q Video Connect has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The 3q-video-connect plugin, version 1.0.0, exhibits a mixed security posture. While it demonstrates good practices by exclusively using prepared statements for SQL queries and having a high percentage of properly escaped output, several critical security concerns are present. The most significant issue is the substantial attack surface exposed without proper authentication or permission checks. Four out of five identified entry points (REST API routes) lack these crucial security measures, making them prime targets for unauthorized access and manipulation. Additionally, the taint analysis reveals flows with unsanitized paths, indicating potential vulnerabilities where user-supplied data could be mishandled, even though no critical or high-severity issues were flagged directly. The absence of any recorded historical vulnerabilities is positive, suggesting a potentially stable codebase in the past, but this is overshadowed by the current static analysis findings. The plugin's strength lies in its database interaction security, but its significant reliance on insecure entry points necessitates immediate attention.

Key Concerns

  • REST API routes without permission callbacks
  • Flows with unsanitized paths
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

3Q Video Connect Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

3Q Video Connect Release Timeline

v1.0
Code Analysis
Analyzed Apr 16, 2026

3Q Video Connect Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
10
100 escaped
Nonce Checks
0
Capability Checks
0
File Operations
4
External Requests
0
Bundled Libraries
0

Output Escaping

91% escaped110 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
p3qvc_display_settings (classes/P3QVC_Setup.class.php:208)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
4 unprotected

3Q Video Connect Attack Surface

Entry Points5
Unprotected4

REST API Routes 4

GET/wp-json/3q-video-connect/v1getVideoList/jsonclasses/P3QVC_API.class.php:111
GET/wp-json/3q-video-connect/v1getVideoList/htmlclasses/P3QVC_API.class.php:115
GET/wp-json/3q-video-connect/v1getChannelList/htmlclasses/P3QVC_API.class.php:119
GET/wp-json/3q-video-connect/v1getUploadForm/htmlclasses/P3QVC_API.class.php:123

Shortcodes 1

[3q] classes/P3QVC_Setup.class.php:15
WordPress Hooks 9
actionrest_api_initclasses/P3QVC_API.class.php:50
actionadmin_initclasses/P3QVC_Setup.class.php:10
actionadmin_menuclasses/P3QVC_Setup.class.php:11
actionwp_enqueue_scriptsclasses/P3QVC_Setup.class.php:14
actionadmin_headclasses/P3QVC_Setup.class.php:132
actionadmin_initclasses/P3QVC_Setup.class.php:133
actionmedia_buttonsclasses/P3QVC_Setup.class.php:134
actionadmin_footerclasses/P3QVC_Setup.class.php:135
filtermce_external_pluginsclasses/P3QVC_Setup.class.php:136
Maintenance & Trust

3Q Video Connect Maintenance & Trust

Maintenance Signals

WordPress version tested5.3.21
Last updatedMar 25, 2020
PHP min version5.2.4
Downloads9K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

3Q Video Connect Developer Profile

3qsdn

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect 3Q Video Connect

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/3q-video-connect/js/sdn-plugin.js/wp-content/plugins/3q-video-connect/js/editor_plugin.js
Script Paths
https://playout.3qsdn.com/player/js/sdnplayer.jshttps://playout.3qsdn.com/player/css/player.css

HTML / DOM Fingerprints

CSS Classes
js3q-player
Data Attributes
data-iddata-projectiddata-playerurldata-projectsecret
JS Globals
threeQ_baseURLthreeQ_rootURLthreeQ_token
Shortcode Output
<div id="player_<script type="text/javascript" src="//playout.3qsdn.com/
FAQ

Frequently Asked Questions about 3Q Video Connect