Authenticate Sponsorware Videos via GitHub Security & Risk Analysis

wordpress.org/plugins/authenticate-sponsorware-videos-via-github

This plugin allows Wordpress users to put a video and description behind Github oauth prompt. It can optionally check for sponsorship of a given organ …

0 active installs v1.2.2 PHP 7.0.0+ WP 5.5.0+ Updated Unknown
blockgithuboauthsponsorvideo
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Authenticate Sponsorware Videos via GitHub Safe to Use in 2026?

Generally Safe

Score 100/100

Authenticate Sponsorware Videos via GitHub has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The plugin "authenticate-sponsorware-videos-via-github" v1.2.2 exhibits a generally strong security posture based on the provided static analysis. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events without proper authentication or permission checks, coupled with 100% of SQL queries using prepared statements, indicates a robust approach to preventing common web vulnerabilities. Furthermore, the high percentage of properly escaped output (82%) and the presence of nonce and capability checks are positive indicators of secure coding practices.

However, a few areas warrant attention. The presence of the "assert" function, while not necessarily a vulnerability in itself, is flagged as a "dangerous function" and could be a potential vector if misused or combined with other weaknesses. The taint analysis showed no critical or high severity flows, which is excellent, but the limited scope of analysis (2 flows) means it's not exhaustive. The plugin's vulnerability history is clean, with no known CVEs, which is a significant strength and suggests a stable and well-maintained codebase over time. Overall, this plugin appears to be secure, with the primary concern being the isolated use of the "assert" function, though its impact is mitigated by other strong security measures.

Key Concerns

  • Presence of dangerous function 'assert'
Vulnerabilities
None known

Authenticate Sponsorware Videos via GitHub Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Authenticate Sponsorware Videos via GitHub Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
0 prepared
Unescaped Output
10
46 escaped
Nonce Checks
2
Capability Checks
1
File Operations
8
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

assertassert($stateToken instanceof Plain);authentication\auth.php:94

Output Escaping

82% escaped56 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
githubauthvideo_serve_video_html (api\serve-player-html.php:4)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Authenticate Sponsorware Videos via GitHub Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 21
actioninitadmin-pages\post_type.php:4
filtermanage_posts_columnsadmin-pages\post_type.php:51
actionmanage_posts_custom_columnadmin-pages\post_type.php:52
actionadd_meta_boxesadmin-pages\post_type.php:84
actionadmin_enqueue_scriptsadmin-pages\post_type.php:85
actionadmin_headadmin-pages\post_type.php:86
actionsave_postadmin-pages\post_type.php:87
actionrest_api_initadmin-pages\post_type.php:299
actionrest_api_initadmin-pages\post_type.php:316
actionadmin_menuadmin-pages\settings.php:12
actionadmin_initadmin-pages\settings.php:13
filterquery_varsgithubauthvideo.php:201
actiontemplate_includegithubauthvideo.php:206
filterwp_kses_allowed_htmlgithubauthvideo.php:292
actioninitgithubauthvideo.php:293
actioninitgithubauthvideo.php:294
actioninitgithubauthvideo.php:295
actioninitgithubauthvideo.php:296
actionwp_enqueue_scriptsgithubauthvideo.php:297
actionadmin_enqueue_scriptsgithubauthvideo.php:298
actionplugins_loadedgithubauthvideo.php:301
Maintenance & Trust

Authenticate Sponsorware Videos via GitHub Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedUnknown
PHP min version7.0.0
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Authenticate Sponsorware Videos via GitHub Developer Profile

OSMD

2 plugins · 100 total installs

100
trust score
Avg Security Score
100/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect Authenticate Sponsorware Videos via GitHub

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/authenticate-sponsorware-videos-via-github/build/index.css/wp-content/plugins/authenticate-sponsorware-videos-via-github/build/style-index.css/wp-content/plugins/authenticate-sponsorware-videos-via-github/build/player/player.min.js/wp-content/plugins/authenticate-sponsorware-videos-via-github/build/admin/settings.min.js
Script Paths
/wp-content/plugins/authenticate-sponsorware-videos-via-github/build/index.js
Version Parameters
authenticate-sponsorware-videos-via-github/build/index.asset.php

HTML / DOM Fingerprints

CSS Classes
wp-block-phonicscore-githubauthvideo
JS Globals
githubauthvideo_player_js_datajs_data
FAQ

Frequently Asked Questions about Authenticate Sponsorware Videos via GitHub