
Changa : Personalized short-video feeds Security & Risk Analysis
wordpress.org/plugins/changa-personalized-short-video-feedsWe help you curate your posts/pages with most liked, trending and most relevent media-rich contents.
Is Changa : Personalized short-video feeds Safe to Use in 2026?
Generally Safe
Score 85/100Changa : Personalized short-video feeds has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The changa-personalized-short-video-feeds v1.4 plugin exhibits a generally good security posture in some areas, with no recorded vulnerabilities in its history and the absence of dangerous functions or external HTTP requests. The code analysis indicates a commitment to secure SQL querying through prepared statements. However, significant concerns arise from the output escaping, where only 24% of outputs are properly escaped. This leaves a substantial portion of the plugin's output vulnerable to cross-site scripting (XSS) attacks, especially given that the sole entry point, a shortcode, does not appear to have explicit capability checks or nonce validation described in the static analysis. While taint analysis didn't reveal critical or high severity unsanitized paths, the low percentage of proper output escaping is a serious weakness. The lack of any recorded vulnerabilities in its history is positive, but it might also indicate limited security auditing or a lack of exposure to sophisticated attacks. Therefore, while the plugin avoids common pitfalls like raw SQL or easily exploitable entry points without authentication, the insufficient output escaping presents a tangible risk.
Key Concerns
- Insufficient output escaping
- No explicit capability checks on shortcode
- No nonce checks on shortcode
Changa : Personalized short-video feeds Security Vulnerabilities
Changa : Personalized short-video feeds Code Analysis
Output Escaping
Data Flow Analysis
Changa : Personalized short-video feeds Attack Surface
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
Changa : Personalized short-video feeds Maintenance & Trust
Maintenance Signals
Community Trust
Changa : Personalized short-video feeds Alternatives
Funbutler Booking System
funbutler-booking
This plugin is used to connect with Funbutler Booking system.
Sudoku – The Game
sudoku-game
Let your website visitors play the famous sudoku game.
Buyte
buyte
Buyte WooCommerce Plugin enables checkout using Apple Pay and Google Pay in a simple, codeless install. Accelerate your customer experience with a bit …
EV Crosswords
ev-crosswords
Easily add crosswords to your Wordpress website, with or without AI help.
Latest Apple Movie Trailers
latest-apple-movie-trailers
Displays the latest movie trailers featured on Apple.com via the RSS Feed.
Changa : Personalized short-video feeds Developer Profile
1 plugin · 0 total installs
How We Detect Changa : Personalized short-video feeds
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/changa-personalized-short-video-feeds/assets/css/all_css_minified.css/wp-content/plugins/changa-personalized-short-video-feeds/assets/js/all_scripts_minified.js/wp-content/plugins/changa-personalized-short-video-feeds/assets/js/all_scripts_minified.jsHTML / DOM Fingerprints
appidslider-typetypedata-ampdevmodedata_appiddata_para<div id="changa-slider"<amp-iframe