
Coviu Video Calls Security & Risk Analysis
wordpress.org/plugins/coviu-video-callsAdd Coviu video calling to your Website.
Is Coviu Video Calls Safe to Use in 2026?
Generally Safe
Score 85/100Coviu Video Calls has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "coviu-video-calls" plugin, version 0.6, exhibits a mixed security posture. On the positive side, the plugin reports zero known CVEs, no unpatched vulnerabilities, and its static analysis shows no dangerous functions, no raw SQL queries, and a limited attack surface with all entry points theoretically protected. It also performs file operations and makes external HTTP requests, which are often points of concern, but these are not flagged as issues in this analysis.
However, significant concerns arise from the taint analysis, which identified four flows with unsanitized paths. While these are not categorized as critical or high severity, the presence of unsanitized paths is a red flag for potential injection vulnerabilities. Furthermore, the output escaping is alarmingly low, with only 5% of outputs properly escaped, suggesting a high risk of Cross-Site Scripting (XSS) vulnerabilities. The plugin also has a limited number of nonce and capability checks relative to the observed outputs and file operations, which could further weaken its security defenses against certain types of attacks.
In conclusion, while the plugin has a clean vulnerability history and a seemingly small attack surface, the serious issues identified in taint analysis (unsanitized paths) and output escaping (low percentage of properly escaped outputs) present a tangible risk. The lack of proper escaping is a critical weakness that could be exploited for XSS attacks, even if the taint flows themselves are not currently deemed critical. The plugin needs immediate attention to address these identified code-level weaknesses to improve its overall security.
Key Concerns
- Taint flows with unsanitized paths
- Low percentage of properly escaped outputs
- Limited nonce checks
- Limited capability checks
Coviu Video Calls Security Vulnerabilities
Coviu Video Calls Code Analysis
Output Escaping
Data Flow Analysis
Coviu Video Calls Attack Surface
WordPress Hooks 5
Maintenance & Trust
Coviu Video Calls Maintenance & Trust
Maintenance Signals
Community Trust
Coviu Video Calls Alternatives
LiveSmart Video Chat Live Video Chat
new-dev-livesmart-video-chat
LiveSmart Video Chat Live Video chat plugin for WordPress that allows visitors to establish live video chat in the browser without download.
FullCall VideoChat
fullcall
This is a one-click installation plugin for FullCall. It is audio and video chat for your website. Easy to use compatible with all modern browsers.
The Ultimate Video Player For WordPress – by Presto Player
presto-player
The Ultimate WordPress Video Player.
Mixed Media Gallery Blocks
simply-gallery-block
Create mixed media galleries with images, HTML5 video, YouTube, Vimeo, and VideoPress — all in one gallery by Simply Gallery.
WP Photo Album Plus
wp-photo-album-plus
This plugin is more than just a photo album plugin, it is a complete, highly customizable multimedia cms and display system.
Coviu Video Calls Developer Profile
1 plugin · 10 total installs
How We Detect Coviu Video Calls
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/coviu-video-calls/coviu-calls.csscoviu-video-calls/coviu-calls.css?ver=HTML / DOM Fingerprints
coviu-video-calls<!-- DISPLAY SESSION LIST --><!-- Add a Video Appointment -->data-coviu-urldata-coviu-api-keydata-coviu-api-key-secretdata-coviu-grantdata-coviu-teamdata-coviu-oauth-url+4 morecvu_client_paramscvu_oauth_params<div class="coviu-video-calls"