Changa : Personalized short-video feeds Security & Risk Analysis

wordpress.org/plugins/changa-personalized-short-video-feeds

We help you curate your posts/pages with most liked, trending and most relevent media-rich contents.

0 active installs v1.4 PHP 7.0+ WP 5.0+ Updated Jul 21, 2021
entertainmentinformativemobile-firstquick-short-video-integration
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Changa : Personalized short-video feeds Safe to Use in 2026?

Generally Safe

Score 85/100

Changa : Personalized short-video feeds has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The changa-personalized-short-video-feeds v1.4 plugin exhibits a generally good security posture in some areas, with no recorded vulnerabilities in its history and the absence of dangerous functions or external HTTP requests. The code analysis indicates a commitment to secure SQL querying through prepared statements. However, significant concerns arise from the output escaping, where only 24% of outputs are properly escaped. This leaves a substantial portion of the plugin's output vulnerable to cross-site scripting (XSS) attacks, especially given that the sole entry point, a shortcode, does not appear to have explicit capability checks or nonce validation described in the static analysis. While taint analysis didn't reveal critical or high severity unsanitized paths, the low percentage of proper output escaping is a serious weakness. The lack of any recorded vulnerabilities in its history is positive, but it might also indicate limited security auditing or a lack of exposure to sophisticated attacks. Therefore, while the plugin avoids common pitfalls like raw SQL or easily exploitable entry points without authentication, the insufficient output escaping presents a tangible risk.

Key Concerns

  • Insufficient output escaping
  • No explicit capability checks on shortcode
  • No nonce checks on shortcode
Vulnerabilities
None known

Changa : Personalized short-video feeds Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Changa : Personalized short-video feeds Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
16
5 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

24% escaped21 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
handle_generic_response (changa.php:149)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Changa : Personalized short-video feeds Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[changa] changa.php:22
WordPress Hooks 5
actionadmin_menuchanga.php:20
actioninitchanga.php:21
filterscript_loader_tagchanga.php:23
actionwp_headchanga.php:98
actionadmin_enqueue_scriptschanga.php:101
Maintenance & Trust

Changa : Personalized short-video feeds Maintenance & Trust

Maintenance Signals

WordPress version tested5.7.0
Last updatedJul 21, 2021
PHP min version7.0
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Changa : Personalized short-video feeds Developer Profile

rajendrab

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Changa : Personalized short-video feeds

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/changa-personalized-short-video-feeds/assets/css/all_css_minified.css/wp-content/plugins/changa-personalized-short-video-feeds/assets/js/all_scripts_minified.js
Script Paths
/wp-content/plugins/changa-personalized-short-video-feeds/assets/js/all_scripts_minified.js

HTML / DOM Fingerprints

Data Attributes
appidslider-typetypedata-ampdevmodedata_appiddata_para
Shortcode Output
<div id="changa-slider"<amp-iframe
FAQ

Frequently Asked Questions about Changa : Personalized short-video feeds