
Vimeotheque – Vimeo WordPress Plugin & Video Gallery Security & Risk Analysis
wordpress.org/plugins/codeflavors-vimeo-video-post-liteImport & embed Vimeo in WordPress. Create video galleries & playlists, auto-sync showcases. Gutenberg blocks & Elementor support.
Is Vimeotheque – Vimeo WordPress Plugin & Video Gallery Safe to Use in 2026?
Generally Safe
Score 96/100Vimeotheque – Vimeo WordPress Plugin & Video Gallery has a strong security track record. Known vulnerabilities have been patched promptly.
The static analysis of codeflavors-vimeo-video-post-lite v2.3.6.1 indicates a relatively low attack surface, with no identified AJAX handlers, REST API routes, shortcodes, or cron events that are accessible without authentication. Furthermore, no dangerous functions, SQL queries susceptible to injection, or file operations were detected. The presence of a bundled TinyMCE library is noted, which is a common and generally safe component. However, a significant concern arises from the output escaping, where only 69% of outputs are properly escaped. This suggests a potential for cross-site scripting vulnerabilities if user-supplied data is not adequately sanitized before being displayed.
The vulnerability history is more concerning. The plugin has a history of three medium-severity vulnerabilities, including Cross-Site Request Forgery (CSRF), SQL Injection, and Cross-Site Scripting (XSS). While there are currently no unpatched CVEs, the recurring types of vulnerabilities indicate a pattern of weaknesses in input validation and output sanitization. The presence of these past vulnerabilities, even if patched, points to areas where the developers have historically struggled to implement robust security measures. The last vulnerability being in December 2025 is a typo and should be interpreted as the last known vulnerability date.
In conclusion, while the current version of the plugin exhibits a small attack surface and good practices regarding SQL queries, the insufficient output escaping in the static analysis and the history of XSS, CSRF, and SQL injection vulnerabilities raise significant security concerns. Users should be cautious due to the potential for XSS and the historical susceptibility to other critical web attack vectors. The absence of identified critical or high-severity taint flows is a positive sign, but it does not fully mitigate the risks highlighted by the output escaping percentage and past vulnerability patterns.
Key Concerns
- Insufficient output escaping detected
- History of SQL Injection vulnerabilities
- History of Cross-Site Scripting vulnerabilities
- History of Cross-Site Request Forgery vulnerabilities
- Bundled library detected (TinyMCE)
Vimeotheque – Vimeo WordPress Plugin & Video Gallery Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Vimeotheque <= 2.3.5.2 - Cross-Site Request Forgery
Vimeotheque <= 2.3.4.2 - Authenticated (Contributor+) SQL Injection
Vimeotheque <= 2.2.1 - Reflected Cross-Site Scripting via 'view' and 'page'
Vimeotheque – Vimeo WordPress Plugin & Video Gallery Code Analysis
Bundled Libraries
Output Escaping
Vimeotheque – Vimeo WordPress Plugin & Video Gallery Attack Surface
WordPress Hooks 38
Maintenance & Trust
Vimeotheque – Vimeo WordPress Plugin & Video Gallery Maintenance & Trust
Maintenance Signals
Community Trust
Vimeotheque – Vimeo WordPress Plugin & Video Gallery Alternatives
All-in-One Video Gallery
all-in-one-video-gallery
The ultimate video player & video gallery plugin for YouTubers, Video Bloggers, Course Creators, Podcasters, and anyone embedding videos on websites.
Vimeography: Vimeo Video Gallery WordPress Plugin
vimeography
The easiest way to create beautiful Vimeo video galleries on your WordPress site.
Meks Video Importer
meks-video-importer
Easily import YouTube and Vimeo videos in bulk to your posts, pages or any custom post type.
Video Gallery Block – Display your videos as a gallery in a professional way
video-gallery-block
Video Gallery Block lets you create responsive YouTube, Vimeo, and HTML5 video galleries with grid layouts, filters, and lightbox in Gutenberg.
Video Gallery – YouTube Gallery & Responsive Video Playlist
youtube-showcase
Responsive video gallery and YouTube gallery for WordPress. Create a video grid or YouTube playlist visually in the block editor. No shortcodes!
Vimeotheque – Vimeo WordPress Plugin & Video Gallery Developer Profile
3 plugins · 3K total installs
How We Detect Vimeotheque – Vimeo WordPress Plugin & Video Gallery
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/codeflavors-vimeo-video-post-lite/themes/default/assets/js/block/app.build.js/wp-content/plugins/codeflavors-vimeo-video-post-lite/themes-series/carousel/assets/js/editor.js/wp-content/plugins/codeflavors-vimeo-video-post-lite/themes-series/default/assets/js/editor.js/wp-content/plugins/codeflavors-vimeo-video-post-lite/themes-series/list/assets/js/editor.jsvimeotheque-theme-default-attributesvimeotheque-series-theme-carousel-editorvimeotheque-series-theme-default-editorvimeotheque-series-theme-list-editorcodeflavors-vimeo-video-post-lite/themes/default/assets/js/block/app.build.js?ver=codeflavors-vimeo-video-post-lite/themes-series/carousel/assets/js/editor.js?ver=codeflavors-vimeo-video-post-lite/themes-series/default/assets/js/editor.js?ver=codeflavors-vimeo-video-post-lite/themes-series/list/assets/js/editor.js?ver=HTML / DOM Fingerprints
cols-3cols-4cols-5cols-6Playlist theme Default script enqueue.Callback function for the block editor script hook thatenqueues block editor Playlist Block attributes extension.Get the image size name based on playlist option 'original_thumbnail_size' value+3 moredata-columnsdata-playbackVimeotheque_Series/wp-json/wp/v2/series