[凹凸曼]播放视频 Security & Risk Analysis

wordpress.org/plugins/apoyl-video

实现复制视频超链接解析播放bilibili视频、优酷视频、youtube视频、腾讯视频、西瓜视频,并且可以统一控制视频大小,操作非常简单不需要去复制视频分享代码,直接到游览器复制URL链接即可,添加到编辑器里,非常方便用户使用。

90 active installs v2.0.0 PHP 7.4+ WP 6.0+ Updated Jan 21, 2026
bilibili%e8%a7%86%e9%a2%91%e8%a7%a3%e6%9e%90%e8%a7%a3%e6%9e%90%e8%a7%86%e9%a2%91videoyoutube
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is [凹凸曼]播放视频 Safe to Use in 2026?

Generally Safe

Score 100/100

[凹凸曼]播放视频 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "apoyl-video" v2.0.0 plugin exhibits a strong security posture based on the provided static analysis. The absence of exposed AJAX handlers, REST API routes, shortcodes, and cron events significantly limits its attack surface. Furthermore, the code signals indicate robust security practices, with no dangerous functions or file operations identified, and all SQL queries utilizing prepared statements. The high percentage of properly escaped output and the presence of a nonce check are positive indicators of secure coding. The taint analysis reveals no critical or high severity issues, suggesting that data flows are handled securely within the plugin.

While the static analysis reveals a generally secure plugin, the complete lack of capability checks is a notable weakness. This means that actions performed by the plugin, even if not directly exposed via an attack surface, might not be restricted to authorized users, potentially leading to unintended consequences or information disclosure if other vulnerabilities are discovered. The vulnerability history also shows no known CVEs, which is a very positive sign, indicating a history of stable and secure development. However, the absence of past vulnerabilities doesn't guarantee future immunity, and the lack of capability checks remains a point of concern.

In conclusion, "apoyl-video" v2.0.0 appears to be a well-developed and secure plugin with a minimal attack surface and good coding practices regarding SQL and output sanitization. The primary area for improvement and potential risk lies in the absence of capability checks, which should be addressed to ensure that all plugin functionalities are properly permissioned. The lack of historical vulnerabilities is commendable and suggests a commitment to security by the developers.

Key Concerns

  • Missing capability checks
Vulnerabilities
None known

[凹凸曼]播放视频 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

[凹凸曼]播放视频 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
14 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

88% escaped16 total outputs
Data Flows
All sanitized

Data Flow Analysis

1 flows
<admin-display> (admin\partials\admin-display.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

[凹凸曼]播放视频 Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionplugins_loadedincludes\video.php:46
actionadmin_menuincludes\video.php:51
actionwp_enqueue_scriptsincludes\video.php:58
actionthe_contentincludes\video.php:59
Maintenance & Trust

[凹凸曼]播放视频 Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 21, 2026
PHP min version7.4
Downloads5K

Community Trust

Rating0/100
Number of ratings0
Active installs90
Developer Profile

[凹凸曼]播放视频 Developer Profile

apoyl

27 plugins · 710 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect [凹凸曼]播放视频

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/apoyl-video/admin/css/admin.css/wp-content/plugins/apoyl-video/admin/js/admin.js/wp-content/plugins/apoyl-video/public/css/public.css
Script Paths
/wp-content/plugins/apoyl-video/admin/js/admin.js
Version Parameters
apoyl-video/admin/css/admin.css?ver=apoyl-video/admin/js/admin.js?ver=apoyl-video/public/css/public.css?ver=

HTML / DOM Fingerprints

CSS Classes
apoyl-video-settings
Data Attributes
data-plugin-name="apoyl-video"
FAQ

Frequently Asked Questions about [凹凸曼]播放视频