
Kaltura All-in-One Video Plugin for WordPress Security & Risk Analysis
wordpress.org/plugins/all-in-one-video-packEasily add full video capabilities to your blog.
Is Kaltura All-in-One Video Plugin for WordPress Safe to Use in 2026?
Generally Safe
Score 85/100Kaltura All-in-One Video Plugin for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of "all-in-one-video-pack" v2.7 reveals a generally strong security posture with no identified attack surface points, dangerous functions, or SQL injection vulnerabilities due to the use of prepared statements. The plugin also shows good practices in output escaping, with 82% of outputs being properly escaped, and no concerning taint analysis results. The absence of any recorded CVEs further suggests a mature and well-maintained codebase.
However, the complete absence of nonce checks and capability checks across all identified entry points (even though there are none reported) is a significant concern. While the current analysis shows no direct attack vectors, this oversight could lead to severe vulnerabilities if any new entry points are introduced or if the attack surface is larger than reported. The reliance on bundled libraries like TinyMCE also warrants attention for potential outdated versions or undiscovered vulnerabilities within them.
Overall, the plugin exhibits good fundamental security practices, particularly regarding data sanitization and output handling. The lack of historical vulnerabilities is a positive indicator. Nevertheless, the missing authentication and authorization checks are a critical gap that significantly lowers its security score and requires immediate attention to prevent potential exploitation in the future.
Key Concerns
- No nonce checks
- No capability checks
- Bundled library (TinyMCE)
- Low output escaping rate (82%)
Kaltura All-in-One Video Plugin for WordPress Security Vulnerabilities
Kaltura All-in-One Video Plugin for WordPress Release Timeline
Kaltura All-in-One Video Plugin for WordPress Code Analysis
Bundled Libraries
Output Escaping
Kaltura All-in-One Video Plugin for WordPress Attack Surface
Maintenance & Trust
Kaltura All-in-One Video Plugin for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
Kaltura All-in-One Video Plugin for WordPress Alternatives
Annoto Plugin for WordPress
annoto
Easily turn you video to social and collaborative.
Peter’s Post Notes
peters-post-notes
Add notes to the "edit post" and "edit page" sidebars. Collaborators can also share notes on the WordPress dashboard.
Admin Page Notes
admin-page-notes
Gives administrators the ability to add notes to posts of any post type (including pages) that are prominently displayed for users editing the site.
Collab Notes
collab-notes
Collab Notes allows administrators to add private notes to pages and posts, with customizable user role permissions.
Data Mafia Dash Note
datamafia-dash-note
Dash Note is a simple editable admin dashboard widget for presenting Wordpress contributors key information.
Kaltura All-in-One Video Plugin for WordPress Developer Profile
2 plugins · 130 total installs
How We Detect Kaltura All-in-One Video Plugin for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/all-in-one-video-pack/all-in-one-video-pack.php/wp-content/plugins/all-in-one-video-pack/chunked-file-upload-jquery/css/jquery.fileupload-ui-kaltura.css/wp-content/plugins/all-in-one-video-pack/chunked-file-upload-jquery/js/jquery.fileupload-kaltura.js/wp-content/plugins/all-in-one-video-pack/chunked-file-upload-jquery/js/jquery.fileupload-kaltura-base.js/wp-content/plugins/all-in-one-video-pack/chunked-file-upload-jquery/js/jquery.fileupload-kaltura.js/wp-content/plugins/all-in-one-video-pack/chunked-file-upload-jquery/js/jquery.fileupload-kaltura-base.js/wp-content/plugins/all-in-one-video-pack/all-in-one-video-pack.php?ver=/wp-content/plugins/all-in-one-video-pack/chunked-file-upload-jquery/css/jquery.fileupload-ui-kaltura.css?ver=/wp-content/plugins/all-in-one-video-pack/chunked-file-upload-jquery/js/jquery.fileupload-kaltura.js?ver=/wp-content/plugins/all-in-one-video-pack/chunked-file-upload-jquery/js/jquery.fileupload-kaltura-base.js?ver=HTML / DOM Fingerprints
entry_detailsuploadBox<!-- here the code to generate Kaltura Seesion comes so that we can pass the KS to the upload widget. --><!-- to ensure security of your account, always generate the KS on the backend, and pass a generated KS to the widget, do not generate a KS in the client side as this will expose your secret keys / passwords. --><!-- additionally, make sure your KS is of type user, and that it permits upload and add actions on uploadToken and entry services. --><!-- continue to pass this, even not used, to trigger chunk upload -->+5 moreuploadBoxIdmaxChunkSizedynamicChunkSizeInitialChunkSizedynamicChunkSizeThresholddynamixChunkSizeMaxTimehost+12 morekalturaAutoloaderKaltura_AutoloaderKaltura_AllInOneVideoPackPluginwidgetcategoryIduploadManager/api_v3/?service=uploadToken&action=upload&format=1