Featured Video for WooCommerce Security & Risk Analysis

wordpress.org/plugins/featured-video-for-woocommerce

Easily add featured videos to your WooCommerce products to increase engagement and conversions.

700 active installs v2.3 PHP 7.0+ WP 4.0+ Updated Oct 3, 2025
videowoocommerceyoutube
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Featured Video for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Featured Video for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7mo ago
Risk Assessment

The "featured-video-for-woocommerce" v2.3 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of any known CVEs, including currently unpatched vulnerabilities, is a significant positive indicator. The code analysis reveals good practices such as 100% of SQL queries using prepared statements and a high percentage of output escaping. Furthermore, the limited attack surface, consisting of a single shortcode with no unprotected entry points, is commendable. The plugin also incorporates two nonce checks, which is a positive step towards preventing CSRF attacks.

However, there are minor areas for improvement. The absence of capability checks, while not directly indicative of a vulnerability in this specific analysis, means that the shortcode's functionality is not restricted based on user roles. A comprehensive security review would typically expect some form of capability checks for sensitive operations. The taint analysis, though showing no critical or high severity issues, only analyzed a small number of flows, leaving room for potential undiscovered issues.

In conclusion, "featured-video-for-woocommerce" v2.3 appears to be a relatively secure plugin with a focus on preventing common vulnerabilities like SQL injection and XSS. The lack of a vulnerability history further reinforces this. The primary area for enhancement would be the consideration of capability checks for its shortcode to further harden its security and reduce the potential for unauthorized access to its features.

Key Concerns

  • Missing capability checks on shortcode
  • Limited taint analysis flow coverage
  • 86% output escaping (potential for 14% to be unescaped)
Vulnerabilities
None known

Featured Video for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Featured Video for WooCommerce Release Timeline

v2.3.0
v2.2.0
v2.1.2
v2.1.1
v2.1.0
v2.0.0
Code Analysis
Analyzed Mar 16, 2026

Featured Video for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
25 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

86% escaped29 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
save_options (admin\class-wcfv-settings.php:111)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Featured Video for WooCommerce Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[wcfv] public\class-wcfv-public.php:194
WordPress Hooks 12
actionplugins_loadedincludes\class-wcfv.php:153
actionadmin_enqueue_scriptsincludes\class-wcfv.php:168
actionadmin_enqueue_scriptsincludes\class-wcfv.php:169
actionwoocommerce_product_data_tabsincludes\class-wcfv.php:171
actionwoocommerce_product_data_panelsincludes\class-wcfv.php:172
actionsave_postincludes\class-wcfv.php:173
actionadmin_post_save_optionsincludes\class-wcfv.php:188
actionadmin_menuincludes\class-wcfv.php:189
actionwp_enqueue_scriptsincludes\class-wcfv.php:204
actionwp_enqueue_scriptsincludes\class-wcfv.php:205
actioninitincludes\class-wcfv.php:207
filterwoocommerce_single_product_image_thumbnail_htmlincludes\class-wcfv.php:209
Maintenance & Trust

Featured Video for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedOct 3, 2025
PHP min version7.0
Downloads59K

Community Trust

Rating100/100
Number of ratings10
Active installs700
Developer Profile

Featured Video for WooCommerce Developer Profile

Foad Adeli

3 plugins · 760 total installs

92
trust score
Avg Security Score
97/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Featured Video for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/featured-video-for-woocommerce/admin/css/wcfv-admin.css/wp-content/plugins/featured-video-for-woocommerce/admin/js/wcfv-admin.js
Version Parameters
wcfv-admin.css?ver=wcfv-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
wcfv_product_datahidden
Data Attributes
data-type="url"autocomplete="off"data_type="url"
JS Globals
wcfv_data
FAQ

Frequently Asked Questions about Featured Video for WooCommerce