Aparat WordPress Video Feed Plugin Security & Risk Analysis

wordpress.org/plugins/aparat-feed

Easily display the latest videos from any Aparat channel on your WordPress site with a lightweight, fast and responsive Aparat video WordPress plugin.

70 active installs v1.3.1 PHP 7.4+ WP 6.0+ Updated Feb 14, 2026
aparataparat-videolatest-postsvideo-widget%d8%a2%d9%be%d8%a7%d8%b1%d8%a7%d8%aa
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Aparat WordPress Video Feed Plugin Safe to Use in 2026?

Generally Safe

Score 100/100

Aparat WordPress Video Feed Plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The aparat-feed v1.3.1 plugin demonstrates a strong adherence to secure coding practices in its static analysis. The absence of any identified dangerous functions, raw SQL queries, file operations, and a commitment to 100% output escaping are significant strengths. The plugin also avoids bundling external libraries, which can often be a source of vulnerabilities. The limited attack surface, with zero identified AJAX handlers, REST API routes, shortcodes, or cron events without proper checks, further contributes to a generally secure posture. The external HTTP request, while present, is a single point and its specific function would require further inspection to determine inherent risk. Crucially, the plugin has no recorded vulnerability history, indicating a stable and likely well-maintained codebase. However, the complete absence of nonce checks and capability checks across all identified entry points (though there are none in this analysis) is a significant concern. If any entry points were to be introduced or discovered later, this would leave them unprotected against common attacks like CSRF. The zero taint flows analyzed also suggest a limited scope of analysis or a very simple plugin, rather than a guarantee of complete taint-free operation.

While the plugin's current state is highly positive due to its proactive secure coding, the lack of implemented security checks for potential future entry points is a notable weakness. The single external HTTP request is a minor area for scrutiny, but without further context, it's difficult to quantify its risk. The overall security posture is good in terms of implemented code, but there are foundational security mechanisms that are entirely absent, which could pose a risk if the plugin's functionality expands or its attack surface is underestimated. The absence of any historical vulnerabilities is a strong positive indicator, suggesting ongoing diligence or a fortunate lack of exploitation targets.

Key Concerns

  • No nonce checks implemented
  • No capability checks implemented
  • Single external HTTP request without context
Vulnerabilities
None known

Aparat WordPress Video Feed Plugin Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Aparat WordPress Video Feed Plugin Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
122 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

100% escaped122 total outputs
Attack Surface

Aparat WordPress Video Feed Plugin Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadmin_enqueue_scriptsincludes\AparatFeed\AparatFeedWidget\class-aparat-feed-widget.php:19
actionwp_enqueue_scriptsincludes\AparatFeed\AparatFeedWidget\class-aparat-feed-widget.php:20
actionadmin_enqueue_scriptsincludes\AparatFeed\class-aparat-feed.php:73
actionwp_enqueue_scriptsincludes\AparatFeed\class-aparat-feed.php:76
actionwidgets_initincludes\AparatFeed\class-aparat-feed.php:79
Maintenance & Trust

Aparat WordPress Video Feed Plugin Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 14, 2026
PHP min version7.4
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs70
Developer Profile

Aparat WordPress Video Feed Plugin Developer Profile

ParsMizban

4 plugins · 2K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Aparat WordPress Video Feed Plugin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/aparat-feed/includes/AparatFeed/AparatFeedWidget/assets/admin/css/style.css/wp-content/plugins/aparat-feed/includes/AparatFeed/AparatFeedWidget/assets/admin/css/style-rtl.css/wp-content/plugins/aparat-feed/includes/AparatFeed/AparatFeedWidget/assets/admin/js/script.js/wp-content/plugins/aparat-feed/includes/AparatFeed/AparatFeedWidget/assets/public/css/style.css/wp-content/plugins/aparat-feed/includes/AparatFeed/AparatFeedWidget/assets/public/css/style-rtl.css
Script Paths
/wp-content/plugins/aparat-feed/includes/AparatFeed/AparatFeedWidget/assets/admin/js/script.js/wp-content/plugins/aparat-feed/includes/AparatFeed/AparatFeedWidget/assets/public/js/script.js

HTML / DOM Fingerprints

CSS Classes
aparat-feed-widgetddaf-widget-formddaf-sectionddaf-section-topddaf-top-actionddaf-action-indicatorddaf-section-titleddaf-section-heading+8 more
Data Attributes
data-fieldsetdata-fieldset-id
JS Globals
AparatFeedAparatFeed\DediData\Plugin_AutoloaderAparatFeed\AparatFeedWidget\Aparat_Feed_Widget
FAQ

Frequently Asked Questions about Aparat WordPress Video Feed Plugin