Fastevo MP2 Security & Risk Analysis

wordpress.org/plugins/fastevo-mp2

Protect your WordPress video content with Fastevo MP2 media protection service.

0 active installs v1.0.1 PHP 7.4+ WP 5.8+ Updated Apr 22, 2025
drmmediaprotectionuploadvideo
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Fastevo MP2 Safe to Use in 2026?

Generally Safe

Score 92/100

Fastevo MP2 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The fastevo-mp2 v1.0.1 plugin exhibits a strong security posture based on the provided static analysis. All identified entry points, including AJAX handlers and REST API routes, appear to have proper authentication and permission checks, which is a significant strength. Furthermore, the code demonstrates excellent practices regarding SQL queries, exclusively using prepared statements, and all output is properly escaped, mitigating common injection and XSS vulnerabilities. The absence of dangerous functions and file operations further contributes to its secure design.

Concerns are minimal. The plugin makes 7 external HTTP requests, which, while not inherently a vulnerability, represent a potential attack vector if the remote endpoints are compromised or if the plugin doesn't handle these requests securely. The presence of TinyMCE as a bundled library could be a minor concern if it's outdated or susceptible to known vulnerabilities, though this is not explicitly detailed in the analysis. The taint analysis reporting zero flows is reassuring, indicating no obvious unhandled data propagation issues.

The plugin's vulnerability history is completely clear, with zero known CVEs. This, combined with the robust static analysis findings, suggests a well-maintained and secure codebase. However, the lack of historical data also means we cannot assess how the plugin has historically responded to security issues. Overall, fastevo-mp2 v1.0.1 appears to be a secure plugin with strong adherence to security best practices, with the external HTTP requests being the primary area for potential scrutiny.

Key Concerns

  • External HTTP requests detected
  • Bundled library (TinyMCE)
Vulnerabilities
None known

Fastevo MP2 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Fastevo MP2 Release Timeline

v1.0.1Current
v1.0
Code Analysis
Analyzed Apr 16, 2026

Fastevo MP2 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
105 escaped
Nonce Checks
5
Capability Checks
16
File Operations
0
External Requests
7
Bundled Libraries
1

Bundled Libraries

TinyMCE

Output Escaping

100% escaped105 total outputs
Attack Surface

Fastevo MP2 Attack Surface

Entry Points10
Unprotected0

AJAX Handlers 4

authwp_ajax_fastevo_mp2_get_player_configurationsincludes/class-fastevo-mp2-classic-editor.php:17
authwp_ajax_fastevo_mp2_browse_contentincludes/class-fastevo-mp2-classic-editor.php:18
authwp_ajax_fastevo_mp2_create_upload_tokenincludes/class-fastevo-mp2-classic-editor.php:19
authwp_ajax_fastevo_mp2_create_folderincludes/class-fastevo-mp2-classic-editor.php:20

REST API Routes 5

POST/wp-json/fastevo-mp2/v1/previewincludes/class-fastevo-mp2-block.php:187
GET/wp-json/fastevo-mp2/v1/player-configurationsincludes/class-fastevo-mp2-block.php:197
GET/wp-json/fastevo-mp2/v1/list-contentsincludes/class-fastevo-mp2-block.php:207
POST/wp-json/fastevo-mp2/v1/create-upload-tokenincludes/class-fastevo-mp2-block.php:217
POST/wp-json/fastevo-mp2/v1/create-folderincludes/class-fastevo-mp2-block.php:227

Shortcodes 1

[fastevo_mp2] includes/class-fastevo-mp2-shortcode.php:11
WordPress Hooks 13
actionplugins_loadedfastevo-mp2.php:45
actioninitincludes/class-fastevo-mp2-block.php:12
actionenqueue_block_editor_assetsincludes/class-fastevo-mp2-block.php:15
actionrest_api_initincludes/class-fastevo-mp2-block.php:18
actionadmin_initincludes/class-fastevo-mp2-classic-editor.php:11
actionadmin_enqueue_scriptsincludes/class-fastevo-mp2-classic-editor.php:14
filtermce_buttonsincludes/class-fastevo-mp2-classic-editor.php:176
filtermce_external_pluginsincludes/class-fastevo-mp2-classic-editor.php:179
actionadmin_menuincludes/class-fastevo-mp2-settings.php:14
actionadmin_initincludes/class-fastevo-mp2-settings.php:15
actionadmin_enqueue_scriptsincludes/class-fastevo-mp2-settings.php:16
actionadmin_enqueue_scriptsincludes/class-fastevo-mp2-settings.php:17
actionadmin_noticesincludes/class-fastevo-mp2-settings.php:18
Maintenance & Trust

Fastevo MP2 Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedApr 22, 2025
PHP min version7.4
Downloads455

Community Trust

Rating100/100
Number of ratings1
Active installs0
Developer Profile

Fastevo MP2 Developer Profile

fastevo

1 plugin · 0 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Fastevo MP2

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/fastevo-mp2/build/fastevo-mp2.asset.php
Script Paths
/wp-content/plugins/fastevo-mp2/build/fastevo-mp2.js

HTML / DOM Fingerprints

Shortcode Output
[fastevo_mp2 src="your_media_url"][fastevo_mp2]
FAQ

Frequently Asked Questions about Fastevo MP2