
Aparat Video Shortcode Security & Risk Analysis
wordpress.org/plugins/aparat-shortcodeAdd [aparat] shortcode to WordPress for easy video sharing in WordPress
Is Aparat Video Shortcode Safe to Use in 2026?
Use With Caution
Score 63/100Aparat Video Shortcode has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The 'aparat-shortcode' plugin exhibits a generally good security posture with no immediate critical risks identified through static code analysis. It demonstrates strong adherence to secure coding practices, as evidenced by the absence of dangerous functions, raw SQL queries, unescaped output, file operations, and external HTTP requests. The complete lack of taint analysis findings further suggests that user input is likely handled safely within the analyzed code paths.
However, a significant concern arises from the plugin's vulnerability history. The presence of one unpatched medium-severity CVE, specifically a Cross-Site Scripting (XSS) vulnerability, indicates a past weakness that has not been addressed. While static analysis found no XSS issues in the current version (0.2.4), the historical pattern of XSS vulnerabilities, coupled with the fact that one remains unpatched, suggests a potential for recurring issues or a delayed patching process within the plugin's development lifecycle. The absence of any capability checks or nonce checks on its entry points (shortcodes) is a minor concern, but given the absence of other direct vulnerabilities in static analysis, this is less critical.
In conclusion, while the code itself appears to be written with good security practices, the unpatched vulnerability is a serious drawback. Users should be aware of this history and exercise caution, prioritizing the resolution of the identified CVE. The plugin's strengths lie in its secure coding habits for the current version, but its weakness lies in its maintenance and response to past security flaws.
Key Concerns
- Unpatched medium severity CVE
- No capability checks on entry points
- No nonce checks on entry points
Aparat Video Shortcode Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Aparat Video Shortcode <= 0.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
Aparat Video Shortcode Code Analysis
Bundled Libraries
Aparat Video Shortcode Attack Surface
Shortcodes 2
WordPress Hooks 2
Maintenance & Trust
Aparat Video Shortcode Maintenance & Trust
Maintenance Signals
Community Trust
Aparat Video Shortcode Alternatives
Aparat for WordPress
wp-aparat
Displaying Aparat videos on website content, along with a widget for showing a list of channel videos.
TechGasp Video Master
vimeo-master
TechGasp Video Master for let's you integrate the superb Vimeo Video quality into any Wordpress widget position. Only for professional websites.
WP Theater
wp-theater
Shortcodes for YouTube and Vimeo. Includes embeds, "Theater" embed, thumbed previews, playlist, channel, user uploads and groups.
Auto Last Youtube Video
auto-last-youtube-video
This plugin provides both Widget and Shortcode to show latest videos from any public Youtube channel.
Lazy load videos and sticky control
lazy-load-videos-and-sticky-control
Lazy load and sticky your video. Super-easy and fun!
Aparat Video Shortcode Developer Profile
1 plugin · 50 total installs
How We Detect Aparat Video Shortcode
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/aparat-shortcode/tinyMCE/editor_plugin.jsHTML / DOM Fingerprints
<iframe src="http://www.aparat.com/video/video/embed/videohash//vt/frame"