
Audio/Video Bonus Pack Security & Risk Analysis
wordpress.org/plugins/audio-video-bonus-packAudio/Video extras not found in WordPress core.
Is Audio/Video Bonus Pack Safe to Use in 2026?
Generally Safe
Score 85/100Audio/Video Bonus Pack has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "audio-video-bonus-pack" plugin version 0.1 exhibits significant security concerns primarily due to its unprotected entry points and the presence of dangerous functions. The static analysis reveals three AJAX handlers, all lacking authentication checks, creating a substantial attack surface that could be exploited by unauthenticated users. Furthermore, the use of the `exec` function is a critical red flag, as it allows for arbitrary command execution on the server if not handled with extreme care and robust sanitization, which is not evident from the provided data.
While the plugin demonstrates good practices in SQL query handling (100% prepared statements) and does not appear to have any known past vulnerabilities, these strengths are heavily overshadowed by the identified risks. The taint analysis did not reveal critical or high-severity issues, but the single unsanitized path flow warrants attention, especially in conjunction with the exposed AJAX endpoints and the `exec` function. The limited number of known CVEs and the absence of historical vulnerabilities are positive indicators, suggesting the developer might be responsive to security issues, but the current version's posture is weak and requires immediate attention to secure its exposed functionalities.
Key Concerns
- Unprotected AJAX handlers
- Use of dangerous 'exec' function
- Flow with unsanitized paths
- Unescaped output
Audio/Video Bonus Pack Security Vulnerabilities
Audio/Video Bonus Pack Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
Audio/Video Bonus Pack Attack Surface
AJAX Handlers 3
WordPress Hooks 13
Maintenance & Trust
Audio/Video Bonus Pack Maintenance & Trust
Maintenance Signals
Community Trust
Audio/Video Bonus Pack Alternatives
Mixed Media Gallery Blocks
simply-gallery-block
Create mixed media galleries with images, HTML5 video, YouTube, Vimeo, and VideoPress — all in one gallery by Simply Gallery.
Lean Player – Video and Audio Player for WordPress, Elementor, Block Editor and Classic Editor
az-video-and-audio-player-addon-for-elementor
WordPress Video Player & Audio Player plugin - simple, lightweight and customizable HTML5, YouTube, Vimeo & mp3 media player that supports all devices
GamiPress – Multimedia Content
gamipress-multimedia-content
Add activity triggers based on multimedia content creation and interaction
Able Player, accessible HTML5 media player
ableplayer
Accessible HTML5 media player
Correct Audio/Video Uploads
correct-audio-video-uploads
Restores the ability to upload audio & video files in recent minor WordPress updates.
Audio/Video Bonus Pack Developer Profile
8 plugins · 210 total installs
How We Detect Audio/Video Bonus Pack
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/audio-video-bonus-pack/features/transcoding/css/transcoding.css/wp-content/plugins/audio-video-bonus-pack/features/soundcloud/css/soundcloud.css/wp-content/plugins/audio-video-bonus-pack/features/soundcloud/js/soundcloud.js/wp-content/plugins/audio-video-bonus-pack/features/transcoding/js/transcoding.js/wp-content/plugins/audio-video-bonus-pack/features/soundcloud/js/soundcloud.jsaudio-video-bonus-pack/style.css?ver=audio-video-bonus-pack/features/transcoding/css/transcoding.css?ver=audio-video-bonus-pack/features/soundcloud/css/soundcloud.css?ver=audio-video-bonus-pack/features/transcoding/js/transcoding.js?ver=audio-video-bonus-pack/features/soundcloud/js/soundcloud.js?ver=HTML / DOM Fingerprints
av-settings-section<!-- 248c57e7f54fb15812a11f34afd88c92 -->name="av_transcoding_enabled"name="av_soundcloud_manager_enabled"/wp-json/audio-video-bonus-pack/v1/settings