Lottie Player – Add Interactive Lottie Animations with Block Support Security & Risk Analysis

wordpress.org/plugins/embed-lottie-player

Lottie Player lets you embed any type of LottieFiles animations into WordPress Gutenberg blocks. Enhances your website with dynamic motion graphics.

5K active installs v1.2.4 PHP 7.1+ WP 6.5+ Updated Mar 5, 2026
animationsblockgutenberg-blocklottiemotion
99
A · Safe
CVEs total1
Unpatched0
Last CVEApr 23, 2025
Download
Safety Verdict

Is Lottie Player – Add Interactive Lottie Animations with Block Support Safe to Use in 2026?

Generally Safe

Score 99/100

Lottie Player – Add Interactive Lottie Animations with Block Support has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Apr 23, 2025Updated 29d ago
Risk Assessment

The "embed-lottie-player" plugin v1.2.4 exhibits a strong security posture in its current static analysis, with no identified dangerous functions, file operations, or external HTTP requests. All SQL queries utilize prepared statements, and all output is properly escaped, indicating good development practices for sanitization. The presence of nonce checks further strengthens its defense against common web vulnerabilities. Taint analysis shows no concerning flows, suggesting input handling is robust.

However, the plugin's vulnerability history is a significant concern. A known medium severity vulnerability, identified as Cross-Site Scripting (XSS), was recorded relatively recently. While this specific vulnerability is currently patched, its existence and type suggest potential for input validation issues. The plugin's current static analysis showing zero unprotected entry points is positive, but it's crucial to acknowledge the past XSS vulnerability, which might indicate a need for continuous vigilance and potentially more comprehensive input sanitization strategies, especially if new entry points or functionalities are added in the future.

In conclusion, the plugin demonstrates good current coding practices. Its strengths lie in its clean code and proper handling of SQL and output. The primary weakness stems from its past XSS vulnerability, which warrants attention and careful monitoring. While the current version appears secure based on the provided data, the history suggests a need for ongoing security reviews.

Key Concerns

  • Medium severity XSS vulnerability in history
  • Bundled Freemius library
Vulnerabilities
1

Lottie Player – Add Interactive Lottie Animations with Block Support Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-2579medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Lottie Player <= 1.1.8 - Authenticated (Author+) Stored Cross-Site Scripting via File Upload

Apr 23, 2025 Patched in 1.2.0 (7d)
Code Analysis
Analyzed Mar 16, 2026

Lottie Player – Add Interactive Lottie Animations with Block Support Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
5 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Freemius

Output Escaping

100% escaped5 total outputs
Attack Surface

Lottie Player – Add Interactive Lottie Animations with Block Support Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actionadmin_menuincludes\admin\SubMenu.php:8
filterplugin_row_metaplugin.php:41
actioninitplugin.php:42
filterblock_categories_allplugin.php:43
actionadmin_enqueue_scriptsplugin.php:44
actionenqueue_block_editor_assetsplugin.php:45
actionenqueue_block_assetsplugin.php:46
filterplugin_action_linksplugin.php:48
filterdefault_titleplugin.php:49
filterdefault_contentplugin.php:50
Maintenance & Trust

Lottie Player – Add Interactive Lottie Animations with Block Support Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 5, 2026
PHP min version7.1
Downloads87K

Community Trust

Rating100/100
Number of ratings4
Active installs5K
Developer Profile

Lottie Player – Add Interactive Lottie Animations with Block Support Developer Profile

colorlibplugins

120 plugins · 738K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
140 days
View full developer profile
Detection Fingerprints

How We Detect Lottie Player – Add Interactive Lottie Animations with Block Support

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/embed-lottie-player/build/admin/dashboard.css/wp-content/plugins/embed-lottie-player/build/admin/dashboard.js/wp-content/plugins/embed-lottie-player/public/js/dotlottie-player.js/wp-content/plugins/embed-lottie-player/public/js/lottie-interactivity.min.js
Script Paths
/wp-content/plugins/embed-lottie-player/build/admin/dashboard.js/wp-content/plugins/embed-lottie-player/public/js/dotlottie-player.js/wp-content/plugins/embed-lottie-player/public/js/lottie-interactivity.min.js
Version Parameters
embed-lottie-player/build/admin/dashboard.css?ver=embed-lottie-player/build/admin/dashboard.js?ver=embed-lottie-player/public/js/dotlottie-player.js?ver=embed-lottie-player/public/js/lottie-interactivity.min.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-info
JS Globals
lpbpipechecklpbpricingurl
FAQ

Frequently Asked Questions about Lottie Player – Add Interactive Lottie Animations with Block Support