
Able Player, accessible HTML5 media player Security & Risk Analysis
wordpress.org/plugins/ableplayerAccessible HTML5 media player
Is Able Player, accessible HTML5 media player Safe to Use in 2026?
Generally Safe
Score 98/100Able Player, accessible HTML5 media player has a strong security track record. Known vulnerabilities have been patched promptly.
The Ableplayer plugin v2.3.0 exhibits a generally good security posture based on static analysis, with strong adherence to secure coding practices such as the exclusive use of prepared statements for SQL queries and a high percentage of properly escaped output. The attack surface is minimal, with only one shortcode identified and no unprotected entry points. The absence of dangerous functions, file operations, and external HTTP requests further strengthens its security. However, the plugin's vulnerability history is a significant concern. With two known medium-severity CVEs, both related to Cross-Site Scripting (XSS), and a recent vulnerability dated in the near future, it indicates a recurring pattern of input sanitization issues. While these vulnerabilities are currently marked as patched, the history suggests a need for continued vigilance and robust testing to prevent future occurrences. The static analysis shows no critical or high severity taint flows, which is positive, but the past XSS vulnerabilities highlight that subtle input sanitization flaws can still emerge. The presence of nonce checks and capability checks (though limited in static analysis scope) is also a positive indicator of security awareness.
Key Concerns
- Medium severity CVEs with XSS history
- Recent vulnerability history (2025-04-24)
Able Player, accessible HTML5 media player Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Able Player, accessible HTML5 media player <= 1.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via preload Parameter
Able Player <= 1.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
Able Player, accessible HTML5 media player Code Analysis
Output Escaping
Able Player, accessible HTML5 media player Attack Surface
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
Able Player, accessible HTML5 media player Maintenance & Trust
Maintenance Signals
Community Trust
Able Player, accessible HTML5 media player Alternatives
Mixed Media Gallery Blocks
simply-gallery-block
Create mixed media galleries with images, HTML5 video, YouTube, Vimeo, and VideoPress — all in one gallery by Simply Gallery.
Lean Player – Video and Audio Player for WordPress, Elementor, Block Editor and Classic Editor
az-video-and-audio-player-addon-for-elementor
WordPress Video Player & Audio Player plugin - simple, lightweight and customizable HTML5, YouTube, Vimeo & mp3 media player that supports all devices
PlayerJS
playerjs
The official plugin for PlayerJS.com - video & audio player builder. Make an awesome player for your website for free.
GamiPress – Multimedia Content
gamipress-multimedia-content
Add activity triggers based on multimedia content creation and interaction
HTML5 Videos
html5-videos
Easily embed HTML5 videos from the Media Library into posts and pages.
Able Player, accessible HTML5 media player Developer Profile
6 plugins · 96K total installs
How We Detect Able Player, accessible HTML5 media player
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ableplayer/assets/css/media.css/wp-content/plugins/ableplayer/assets/js/media.js/wp-content/plugins/ableplayer/build/ableplayer.min.css/wp-content/plugins/ableplayer/build/ableplayer.js/wp-content/plugins/ableplayer/thirdparty/js.cookie.min.js/wp-content/plugins/ableplayer/thirdparty/js.cookie.js/wp-content/plugins/ableplayer/assets/js/admin.js/wp-content/plugins/ableplayer/assets/css/admin.csshttps://player.vimeo.com/api/player.jsableplayer-video?ver=ableplayer?ver=js-cookie?ver=ableplayer-js?ver=ableplayer?ver=HTML / DOM Fingerprints
able-player-containerable-player-errorable-player-controlsable-player-progressable-player-volumeable-player-timeable-player-playable-player-pause+15 moreAble Playeraccessible HTML5 media playerJoe DolsonMIT+7 moredata-able-playerdata-iddata-allow-fullscreendata-autoplaydata-captions-positiondata-heading+16 moreableplayer[able_player[/able_player]