Embed Peertube Playlist Security & Risk Analysis

wordpress.org/plugins/embed-peertube-playlist

Display peertube playlist on your webiste.

100 active installs v1.21 PHP 5.6+ WP 3.5+ Updated Dec 6, 2025
embedgridpeertubeplaylistvideo
99
A · Safe
CVEs total1
Unpatched0
Last CVEJun 22, 2024
Download
Safety Verdict

Is Embed Peertube Playlist Safe to Use in 2026?

Generally Safe

Score 99/100

Embed Peertube Playlist has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Jun 22, 2024Updated 3mo ago
Risk Assessment

The "embed-peertube-playlist" plugin version 1.21 demonstrates a generally good security posture based on the static analysis. A high percentage of SQL queries utilize prepared statements, and output escaping is very well implemented. The absence of critical or high severity taint flows further suggests a lack of immediately exploitable code vulnerabilities. The plugin also has a limited attack surface with no unprotected entry points identified in the static analysis.

However, a medium severity vulnerability (Cross-site Scripting) was recently patched, indicating a past weakness that required remediation. While currently unpatched vulnerabilities are zero, the presence of a past XSS vulnerability is a point of attention. The lack of capability checks on its entry points, despite a small attack surface, represents a potential area for improvement to further harden the plugin against unauthorized actions, even if the current analysis found no direct way to exploit this.

In conclusion, the plugin is in a relatively secure state with strong coding practices in place for SQL and output handling. The recent remediation of a medium severity XSS vulnerability is positive, but it highlights the importance of ongoing vigilance. The primary area for improvement would be the addition of capability checks to its entry points to align with WordPress security best practices.

Key Concerns

  • Missing capability checks on entry points
  • Past medium severity XSS vulnerability history
Vulnerabilities
1

Embed Peertube Playlist Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-4602medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Embed Peertube Playlist <= 1.07 - Authenticated (Editor+) Stored Cross-Site Scripting

Jun 22, 2024 Patched in 1.10 (6d)
Code Analysis
Analyzed Mar 16, 2026

Embed Peertube Playlist Code Analysis

Dangerous Functions
0
Raw SQL Queries
3
10 prepared
Unescaped Output
1
20 escaped
Nonce Checks
3
Capability Checks
0
File Operations
1
External Requests
1
Bundled Libraries
0

SQL Query Safety

77% prepared13 total queries

Output Escaping

95% escaped21 total outputs
Data Flows
All sanitized

Data Flow Analysis

3 flows
playlists_peertube (peertube-playlist.php:93)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Embed Peertube Playlist Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 1

authwp_ajax_remove_playlist_peertubepeertube-playlist.php:151

Shortcodes 1

[playlist_peertube] peertube-playlist.php:173
WordPress Hooks 3
actionadmin_menupeertube-playlist.php:55
actionadmin_print_stylespeertube-playlist.php:85
actionwp_enqueue_scriptspeertube-playlist.php:255
Maintenance & Trust

Embed Peertube Playlist Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 6, 2025
PHP min version5.6
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs100
Developer Profile

Embed Peertube Playlist Developer Profile

manu225

17 plugins · 27K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
29 days
View full developer profile
Detection Fingerprints

How We Detect Embed Peertube Playlist

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/embed-peertube-playlist/css/admin.css/wp-content/plugins/embed-peertube-playlist/css/grid.css
Script Paths
/wp-content/plugins/embed-peertube-playlist/js/admin.js
Version Parameters
embed-peertube-playlist/css/admin.css?ver=embed-peertube-playlist/css/grid.css?ver=

HTML / DOM Fingerprints

REST Endpoints
/api/v1/video-playlists/
FAQ

Frequently Asked Questions about Embed Peertube Playlist