
Easy Video Player Security & Risk Analysis
wordpress.org/plugins/easy-video-playerEasy Video Player is a WordPress video player that allows you to add videos to your WordPress site.
Is Easy Video Player Safe to Use in 2026?
Generally Safe
Score 99/100Easy Video Player has a strong security track record. Known vulnerabilities have been patched promptly.
The "easy-video-player" plugin v1.2.2.13 exhibits a mixed security posture. On the positive side, the static analysis reveals no dangerous functions, no file operations, and all SQL queries utilize prepared statements, indicating good practices in these areas. The plugin also correctly implements nonce and capability checks for its single entry point and avoids external HTTP requests. However, a significant concern is the output escaping, where only 53% of outputs are properly escaped, suggesting a potential for Cross-Site Scripting (XSS) vulnerabilities. The vulnerability history shows two known medium-severity CVEs, both related to XSS, with the most recent one being in late 2023. While currently unpatched vulnerabilities are none, the pattern of past XSS issues, coupled with the static analysis finding of inadequate output escaping, points to a persistent risk in how user-supplied data is handled before being displayed. Therefore, while the plugin demonstrates strengths in areas like SQL injection prevention and secure coding practices for entry points, the ongoing presence and nature of XSS vulnerabilities, exacerbated by partially unescaped output, warrant attention.
Key Concerns
- Inadequate output escaping
- History of medium severity XSS CVEs
Easy Video Player Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Easy Video Player <= 1.2.2.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Easy Video Player <= 1.2.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
Easy Video Player Code Analysis
Output Escaping
Easy Video Player Attack Surface
Shortcodes 1
WordPress Hooks 8
Maintenance & Trust
Easy Video Player Maintenance & Trust
Maintenance Signals
Community Trust
Easy Video Player Alternatives
TurboVideo – Video Player and CDN
turbo-video
Welcome to our Turbo Video WordPress Plug-in, a robust solution designed to optimize video delivery on your WordPress site.
FV Flowplayer Video Player
fv-wordpress-flowplayer
WordPress's most reliable, easy to use and feature-rich video player. Supports responsive design, HTML5, playlists, ads, stats, Vimeo and YouTube.
Flowplayer Video Player
flowplayer6-video-player
Add a video file to WordPress with Flowplayer style. Embed a self-hosted, external or HTML5 compatible responsive video into a page with flowplayer.
FV Player 8
fv-player
WordPress's most reliable, easy to use and feature-rich video player. Supports playlists, ads, stats and user video position saving.
SWFPut – SWFlash Put
swfput
SWFPut provides video players for posts and pages and widget areas, as both HTML5 and flash video.
Easy Video Player Developer Profile
25 plugins · 157K total installs
How We Detect Easy Video Player
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/easy-video-player/css/easy-video-player.css/wp-content/plugins/easy-video-player/js/easy-video-player.js/wp-content/plugins/easy-video-player/js/jquery.jplayer.min.js/wp-content/plugins/easy-video-player/js/jplayer.playlist.min.js/wp-content/plugins/easy-video-player/js/easy-video-player-custom.js/wp-content/plugins/easy-video-player/js/easy-video-player.jseasy-video-player/css/easy-video-player.css?ver=easy-video-player/js/easy-video-player.js?ver=easy-video-player/js/jquery.jplayer.min.js?ver=easy-video-player/js/jplayer.playlist.min.js?ver=easy-video-player/js/easy-video-player-custom.js?ver=HTML / DOM Fingerprints
evp-containerevp-video-wrapper<!-- EASY VIDEO PLAYER SHORTCODE START --><!-- EASY VIDEO PLAYER SHORTCODE END -->data-evp-video-idEVP_SETTINGS<div class="evp-container"><div class="evp-video-wrapper" data-evp-video-id="