
[凹凸曼]播放视频 Security & Risk Analysis
wordpress.org/plugins/apoyl-video实现复制视频超链接解析播放bilibili视频、优酷视频、youtube视频、腾讯视频、西瓜视频,并且可以统一控制视频大小,操作非常简单不需要去复制视频分享代码,直接到游览器复制URL链接即可,添加到编辑器里,非常方便用户使用。
Is [凹凸曼]播放视频 Safe to Use in 2026?
Generally Safe
Score 100/100[凹凸曼]播放视频 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "apoyl-video" v2.0.0 plugin exhibits a strong security posture based on the provided static analysis. The absence of exposed AJAX handlers, REST API routes, shortcodes, and cron events significantly limits its attack surface. Furthermore, the code signals indicate robust security practices, with no dangerous functions or file operations identified, and all SQL queries utilizing prepared statements. The high percentage of properly escaped output and the presence of a nonce check are positive indicators of secure coding. The taint analysis reveals no critical or high severity issues, suggesting that data flows are handled securely within the plugin.
While the static analysis reveals a generally secure plugin, the complete lack of capability checks is a notable weakness. This means that actions performed by the plugin, even if not directly exposed via an attack surface, might not be restricted to authorized users, potentially leading to unintended consequences or information disclosure if other vulnerabilities are discovered. The vulnerability history also shows no known CVEs, which is a very positive sign, indicating a history of stable and secure development. However, the absence of past vulnerabilities doesn't guarantee future immunity, and the lack of capability checks remains a point of concern.
In conclusion, "apoyl-video" v2.0.0 appears to be a well-developed and secure plugin with a minimal attack surface and good coding practices regarding SQL and output sanitization. The primary area for improvement and potential risk lies in the absence of capability checks, which should be addressed to ensure that all plugin functionalities are properly permissioned. The lack of historical vulnerabilities is commendable and suggests a commitment to security by the developers.
Key Concerns
- Missing capability checks
[凹凸曼]播放视频 Security Vulnerabilities
[凹凸曼]播放视频 Code Analysis
Output Escaping
Data Flow Analysis
[凹凸曼]播放视频 Attack Surface
WordPress Hooks 4
Maintenance & Trust
[凹凸曼]播放视频 Maintenance & Trust
Maintenance Signals
Community Trust
[凹凸曼]播放视频 Alternatives
Smartideo
smartideo
Smartideo 是为 WordPress 添加对在线视频支持的一款插件(支持手机、平板等设备HTML5播放)。
The Ultimate Video Player For WordPress – by Presto Player
presto-player
The Ultimate WordPress Video Player.
Advanced WordPress Backgrounds
advanced-backgrounds
Easy to use advanced Parallax, Image and Video backgrounds block plugin with parallax and video support.
WP YouTube Lyte
wp-youtube-lyte
High performance YouTube video, playlist and audio-only embeds which don't slow down your blog and offer optimal accessibility.
All-in-One Video Gallery
all-in-one-video-gallery
The ultimate video player & video gallery plugin for YouTubers, Video Bloggers, Course Creators, Podcasters, and anyone embedding videos on websites.
[凹凸曼]播放视频 Developer Profile
27 plugins · 710 total installs
How We Detect [凹凸曼]播放视频
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/apoyl-video/admin/css/admin.css/wp-content/plugins/apoyl-video/admin/js/admin.js/wp-content/plugins/apoyl-video/public/css/public.css/wp-content/plugins/apoyl-video/admin/js/admin.jsapoyl-video/admin/css/admin.css?ver=apoyl-video/admin/js/admin.js?ver=apoyl-video/public/css/public.css?ver=HTML / DOM Fingerprints
apoyl-video-settingsdata-plugin-name="apoyl-video"