
AM LottiePlayer Security & Risk Analysis
wordpress.org/plugins/am-lottieplayerThe most complete Lottie Player plugin! It is lightweight, versatile and easy to use, and it works with Gutenberg, Divi, Elementor and Flatsome.
Is AM LottiePlayer Safe to Use in 2026?
Generally Safe
Score 99/100AM LottiePlayer has a strong security track record. Known vulnerabilities have been patched promptly.
The "am-lottieplayer" plugin, version 3.6.3, presents a generally positive security posture based on the static analysis. The absence of dangerous functions, SQL queries without prepared statements, file operations, and external HTTP requests are strong indicators of secure coding practices. The high percentage of properly escaped output and the presence of nonce and capability checks further bolster its security. The limited attack surface, with only one shortcode and no unprotected entry points, is also a significant strength.
The vulnerability history, however, reveals a past medium-severity Cross-site Scripting (XSS) vulnerability. While this vulnerability is noted as currently unpatched, the timing of the "last vulnerability" date (2025-04-30) seems to be in the future, which might indicate a data anomaly or that the vulnerability was disclosed recently and a patch is pending. The single CVE, despite being medium severity, warrants attention as it highlights a potential weakness in input handling.
Overall, the plugin demonstrates good security practices in its current codebase. The primary area of concern stems from the past XSS vulnerability, suggesting a need for continued vigilance in input sanitization and output escaping, even if current analysis shows high compliance. Users should ensure they are on the latest version if available to mitigate any previously disclosed vulnerabilities.
Key Concerns
- Past medium severity XSS vulnerability
AM LottiePlayer Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
AM LottiePlayer <= 3.5.3 - Authenticated (Author+) Stored Cross-Site Scripting via Uploaded Lottie File
AM LottiePlayer Code Analysis
Output Escaping
AM LottiePlayer Attack Surface
Shortcodes 1
WordPress Hooks 20
Maintenance & Trust
AM LottiePlayer Maintenance & Trust
Maintenance Signals
Community Trust
AM LottiePlayer Alternatives
LottieFiles
lottiefiles
LottieFiles for WordPress is the easiest way to add Lottie animations to your WordPress website using the Gutenberg editor.
Lottie Player – Add Interactive Lottie Animations with Block Support
embed-lottie-player
Lottie Player lets you embed any type of LottieFiles animations into WordPress Gutenberg blocks. Enhances your website with dynamic motion graphics.
Animentor – Lottie & Bodymovin for Elementor
animentor-lottie-bodymovin-elementor
An Elementor extension that adds a widget for Lottie animations.
LottieFiles – JSON Based Animation Lottie & Bodymovin for Elementor
include-lottie-animation-for-elementor
Creative layout to your site with smaller json file using Lottie animations.
JVM Rich Text Icons
jvm-rich-text-icons
Insert icons anywhere in your content — inline in text, headings, buttons, or as a standalone block.
AM LottiePlayer Developer Profile
2 plugins · 800 total installs
How We Detect AM LottiePlayer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/am-lottieplayer/assets/css/admin.min.css/wp-content/plugins/am-lottieplayer/assets/js/vendor/dotlottie-player.js/wp-content/plugins/am-lottieplayer/assets/js/vendor/dotlottie-player-light.js/wp-content/plugins/am-lottieplayer/assets/js/media.jsam-lottieplayer/assets/css/admin.min.css?ver=am-lottieplayer/assets/js/vendor/dotlottie-player.js?ver=am-lottieplayer/assets/js/vendor/dotlottie-player-light.js?ver=am-lottieplayer/assets/js/media.js?ver=HTML / DOM Fingerprints
am-lottieplayer-dashboard-widgetAM LottiePlayer PluginCopyright (C) 2023-2024, Aarstein Media - support@aarstein.mediaGNU General Public License, version 3 or higher@wordpress-plugin+9 moredata-am-lottieplayer-iddata-am-lottieplayer-srcdata-am-lottieplayer-optionsaamdPHPVariables/wp/v2/media/[am_lottieplayer[am_lottieplayer_vc][am_lottieplayer_elementor]