
Display Embedded Videos by D.Biota Security & Risk Analysis
wordpress.org/plugins/display-embedded-videos-by-dbiotaYou can display a gallery of the embedded Youtube and Vimeo videos within your site. They can be shown chronologically or as a random selection.
Is Display Embedded Videos by D.Biota Safe to Use in 2026?
Generally Safe
Score 85/100Display Embedded Videos by D.Biota has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'display-embedded-videos-by-dbiota' plugin, version 2.0, exhibits several concerning security practices despite a clean vulnerability history. The static analysis reveals a significant attack surface with 4 total entry points, 3 of which are unprotected AJAX handlers. This lack of authentication on these handlers is a major security weakness, as it allows any user, including unauthenticated ones, to trigger these functions, potentially leading to unintended actions or information disclosure.
The code analysis also highlights critical flaws in output handling. With 9 total outputs and 0% properly escaped, there is a high risk of cross-site scripting (XSS) vulnerabilities. This means that user-supplied data, if processed and displayed without proper sanitization, could be used to inject malicious scripts into web pages.
While the plugin has no recorded vulnerabilities (CVEs), this does not guarantee its current security. The absence of a vulnerability history could indicate a lack of thorough auditing or that potential issues have not yet been discovered or exploited. Coupled with the identified code weaknesses, this history should not be interpreted as a sign of robust security. The plugin's reliance on raw SQL queries for a significant portion of its database interactions (71% not using prepared statements) also introduces a risk of SQL injection, although taint analysis did not flag critical or high severity flows in this area.
In conclusion, the plugin's security posture is poor due to unprotected AJAX endpoints and widespread output unescaping, creating significant risks for XSS and unauthorized actions. The lack of historical vulnerabilities should be viewed with caution given these code-level concerns. A thorough audit and remediation of these issues are strongly recommended.
Key Concerns
- Unprotected AJAX handlers
- Unescaped output
- SQL queries not using prepared statements
- Missing nonce checks
- Missing capability checks
Display Embedded Videos by D.Biota Security Vulnerabilities
Display Embedded Videos by D.Biota Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Display Embedded Videos by D.Biota Attack Surface
AJAX Handlers 3
Shortcodes 1
WordPress Hooks 9
Maintenance & Trust
Display Embedded Videos by D.Biota Maintenance & Trust
Maintenance Signals
Community Trust
Display Embedded Videos by D.Biota Alternatives
All-in-One Video Gallery
all-in-one-video-gallery
The ultimate video player & video gallery plugin for YouTubers, Video Bloggers, Course Creators, Podcasters, and anyone embedding videos on websites.
Video Gallery Block – Display your videos as a gallery in a professional way
video-gallery-block
Video Gallery Block lets you create responsive YouTube, Vimeo, and HTML5 video galleries with grid layouts, filters, and lightbox in Gutenberg.
Video gallery and Player
html5-videogallery-plus-player
Easy to add and display your HTML5, YouTube, Vimeo vedio gallery with Magnific Popup to your website. Also work with Gutenberg shortcode block.
Video Gallery by Huzzaz
huzzaz-video-gallery
Create a beautiful video gallery with YouTube, Vimeo, Facebook, and Twitch videos. It looks great on mobile, tablet, or desktop screens and it support …
Video Gallery YouTube Vimeo
new-video-gallery
Create responsive YouTube and Vimeo video galleries with custom layouts, lightbox display, and easy shortcode embedding.
Display Embedded Videos by D.Biota Developer Profile
2 plugins · 20 total installs
How We Detect Display Embedded Videos by D.Biota
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/display-embedded-videos-by-dbiota/display-embedded-videos-by-dbiota.phpdisplay-embedded-videos-by-dbiota/display-embedded-videos-by-dbiota.php?ver=HTML / DOM Fingerprints
id="select_mode"id="input_vids_to_display"id="input_vids_per_line"id="select_more"id="shortcode_generation"id="sc_result"+7 more[display_embedded_videos[display_embedded_videos mode=[display_embedded_videos num_videos=[display_embedded_videos videos_per_line=