
Lottie Player – Add Interactive Lottie Animations with Block Support Security & Risk Analysis
wordpress.org/plugins/embed-lottie-playerLottie Player lets you embed any type of LottieFiles animations into WordPress Gutenberg blocks. Enhances your website with dynamic motion graphics.
Is Lottie Player – Add Interactive Lottie Animations with Block Support Safe to Use in 2026?
Generally Safe
Score 99/100Lottie Player – Add Interactive Lottie Animations with Block Support has a strong security track record. Known vulnerabilities have been patched promptly.
The "embed-lottie-player" plugin v1.2.4 exhibits a strong security posture in its current static analysis, with no identified dangerous functions, file operations, or external HTTP requests. All SQL queries utilize prepared statements, and all output is properly escaped, indicating good development practices for sanitization. The presence of nonce checks further strengthens its defense against common web vulnerabilities. Taint analysis shows no concerning flows, suggesting input handling is robust.
However, the plugin's vulnerability history is a significant concern. A known medium severity vulnerability, identified as Cross-Site Scripting (XSS), was recorded relatively recently. While this specific vulnerability is currently patched, its existence and type suggest potential for input validation issues. The plugin's current static analysis showing zero unprotected entry points is positive, but it's crucial to acknowledge the past XSS vulnerability, which might indicate a need for continuous vigilance and potentially more comprehensive input sanitization strategies, especially if new entry points or functionalities are added in the future.
In conclusion, the plugin demonstrates good current coding practices. Its strengths lie in its clean code and proper handling of SQL and output. The primary weakness stems from its past XSS vulnerability, which warrants attention and careful monitoring. While the current version appears secure based on the provided data, the history suggests a need for ongoing security reviews.
Key Concerns
- Medium severity XSS vulnerability in history
- Bundled Freemius library
Lottie Player – Add Interactive Lottie Animations with Block Support Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Lottie Player <= 1.1.8 - Authenticated (Author+) Stored Cross-Site Scripting via File Upload
Lottie Player – Add Interactive Lottie Animations with Block Support Code Analysis
Bundled Libraries
Output Escaping
Lottie Player – Add Interactive Lottie Animations with Block Support Attack Surface
WordPress Hooks 10
Maintenance & Trust
Lottie Player – Add Interactive Lottie Animations with Block Support Maintenance & Trust
Maintenance Signals
Community Trust
Lottie Player – Add Interactive Lottie Animations with Block Support Alternatives
AKDev Spline animation – Delight your users experience with 3d scroll animations.
akdev-spline-animation
Create Spline 3d scrolling animations with ease and wow your users.
XPAC Lottie Interactive Animations
xpac-lottie-interactive-animation
A powerful tool to add impressive light-weight animations to your website with a Wordpress native site editor, optimized for performance and Full Site …
Spectra Gutenberg Blocks – Website Builder for the Block Editor
ultimate-addons-for-gutenberg
Power-up Gutenberg with advanced blocks for faster website creation. Build your WordPress website effortlessly using powerful building blocks!
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor
kadence-blocks
20+ AI-powered Gutenberg Blocks with endless options, enabling top-notch efficiency for high-performance dynamic website creation.
Page Builder: Pagelayer – Drag and Drop website builder
pagelayer
The most advanced frontend drag & drop page builder. Pagelayer is a light weight but extremely powerful Website Builder.
Lottie Player – Add Interactive Lottie Animations with Block Support Developer Profile
120 plugins · 738K total installs
How We Detect Lottie Player – Add Interactive Lottie Animations with Block Support
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/embed-lottie-player/build/admin/dashboard.css/wp-content/plugins/embed-lottie-player/build/admin/dashboard.js/wp-content/plugins/embed-lottie-player/public/js/dotlottie-player.js/wp-content/plugins/embed-lottie-player/public/js/lottie-interactivity.min.js/wp-content/plugins/embed-lottie-player/build/admin/dashboard.js/wp-content/plugins/embed-lottie-player/public/js/dotlottie-player.js/wp-content/plugins/embed-lottie-player/public/js/lottie-interactivity.min.jsembed-lottie-player/build/admin/dashboard.css?ver=embed-lottie-player/build/admin/dashboard.js?ver=embed-lottie-player/public/js/dotlottie-player.js?ver=embed-lottie-player/public/js/lottie-interactivity.min.js?ver=HTML / DOM Fingerprints
data-infolpbpipechecklpbpricingurl