Aparat Video Shortcode Security & Risk Analysis

wordpress.org/plugins/aparat-shortcode

Add [aparat] shortcode to WordPress for easy video sharing in WordPress

50 active installs v0.2.4 PHP + WP 2.0.2+ Updated Aug 6, 2013
aparatshortcodevideo
63
C · Use Caution
CVEs total1
Unpatched1
Last CVESep 5, 2025
Safety Verdict

Is Aparat Video Shortcode Safe to Use in 2026?

Use With Caution

Score 63/100

Aparat Video Shortcode has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Sep 5, 2025Updated 12yr ago
Risk Assessment

The 'aparat-shortcode' plugin exhibits a generally good security posture with no immediate critical risks identified through static code analysis. It demonstrates strong adherence to secure coding practices, as evidenced by the absence of dangerous functions, raw SQL queries, unescaped output, file operations, and external HTTP requests. The complete lack of taint analysis findings further suggests that user input is likely handled safely within the analyzed code paths.

However, a significant concern arises from the plugin's vulnerability history. The presence of one unpatched medium-severity CVE, specifically a Cross-Site Scripting (XSS) vulnerability, indicates a past weakness that has not been addressed. While static analysis found no XSS issues in the current version (0.2.4), the historical pattern of XSS vulnerabilities, coupled with the fact that one remains unpatched, suggests a potential for recurring issues or a delayed patching process within the plugin's development lifecycle. The absence of any capability checks or nonce checks on its entry points (shortcodes) is a minor concern, but given the absence of other direct vulnerabilities in static analysis, this is less critical.

In conclusion, while the code itself appears to be written with good security practices, the unpatched vulnerability is a serious drawback. Users should be aware of this history and exercise caution, prioritizing the resolution of the identified CVE. The plugin's strengths lie in its secure coding habits for the current version, but its weakness lies in its maintenance and response to past security flaws.

Key Concerns

  • Unpatched medium severity CVE
  • No capability checks on entry points
  • No nonce checks on entry points
Vulnerabilities
1

Aparat Video Shortcode Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-58876medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Aparat Video Shortcode <= 0.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting

Sep 5, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

Aparat Video Shortcode Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

TinyMCE
Attack Surface

Aparat Video Shortcode Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[aparat] aparat-video-shortcut.php:48
[APARAT] aparat-video-shortcut.php:49
WordPress Hooks 2
filtermce_external_pluginsaparat-video-shortcut.php:52
filtermce_buttonsaparat-video-shortcut.php:53
Maintenance & Trust

Aparat Video Shortcode Maintenance & Trust

Maintenance Signals

WordPress version tested3.6.1
Last updatedAug 6, 2013
PHP min version
Downloads7K

Community Trust

Rating100/100
Number of ratings3
Active installs50
Developer Profile

Aparat Video Shortcode Developer Profile

Ali Aghdam

1 plugin · 50 total installs

68
trust score
Avg Security Score
63/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Aparat Video Shortcode

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/aparat-shortcode/tinyMCE/editor_plugin.js

HTML / DOM Fingerprints

Shortcode Output
<iframe src="http://www.aparat.com/video/video/embed/videohash//vt/frame"
FAQ

Frequently Asked Questions about Aparat Video Shortcode