Genesis Featured Video Security & Risk Analysis

wordpress.org/plugins/featured-videos-for-genesis

Replace featured images in a Genesis theme with a featured video from YouTube, Vimeo and other sources.

200 active installs v1.1.5 PHP + WP 3.1.0+ Updated Oct 13, 2021
featured-imagefeatured-videogenesis
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Genesis Featured Video Safe to Use in 2026?

Generally Safe

Score 85/100

Genesis Featured Video has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The plugin 'featured-videos-for-genesis' v1.1.5 exhibits a very strong security posture based on the provided static analysis. The plugin has a remarkably small attack surface with zero identified entry points that lack authentication or permission checks. Furthermore, the code demonstrates excellent security practices by avoiding dangerous functions, performing all SQL queries using prepared statements, and conducting file operations or external HTTP requests. The high percentage of properly escaped output is also a significant positive signal.

While the static analysis reveals no direct vulnerabilities, the absence of capability checks and only one nonce check across all analyzed code is a potential area for concern. This suggests that while the current implementation might not have exploitable flaws, it relies heavily on the WordPress core or theme for authorization, which could become a weakness if the plugin's functionality were to expand or be integrated with other systems. The vulnerability history is entirely clean, with no known CVEs, which is an excellent indicator of the developer's diligence in maintaining the code's security.

In conclusion, 'featured-videos-for-genesis' v1.1.5 is exceptionally well-secured in its current form, with no immediate exploitable vulnerabilities apparent. Its strengths lie in its minimal attack surface and robust handling of core security primitives like SQL and output escaping. The main, albeit minor, weakness is the limited implementation of its own capability and nonce checks, which could be improved for even greater resilience. However, given the lack of any recorded vulnerabilities and the overall clean analysis, the plugin can be considered very low risk.

Key Concerns

  • Only one nonce check found
  • No capability checks found
  • 93% output escaping is good, but not 100%
Vulnerabilities
None known

Genesis Featured Video Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Genesis Featured Video Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
16
205 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

93% escaped221 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
save_gfv_settings (includes\gfv-settings.php:76)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Genesis Featured Video Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 13
actionadmin_initgenesis-featured-video.php:29
actionplugins_loadedgenesis-featured-video.php:33
actionwp_enqueue_scriptsgenesis-featured-video.php:38
actionadmin_initincludes\gfv-metabox.php:6
actionsave_postincludes\gfv-metabox.php:23
filtergfv_post_typesincludes\gfv-post-types.php:26
actionadmin_menuincludes\gfv-settings.php:8
actionadmin_initincludes\gfv-settings.php:10
actionadmin_initincludes\gfv-settings.php:98
actioninitincludes\video-format.php:11
actiongenesis_entry_contentincludes\video-image.php:6
actionpre_get_postsincludes\video-image.php:41
actionwidgets_initincludes\widget.php:6
Maintenance & Trust

Genesis Featured Video Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedOct 13, 2021
PHP min version
Downloads22K

Community Trust

Rating100/100
Number of ratings5
Active installs200
Developer Profile

Genesis Featured Video Developer Profile

AMP-MODE

15 plugins · 13K total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Genesis Featured Video

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/featured-videos-for-genesis/css/gfv-style.css

HTML / DOM Fingerprints

CSS Classes
gfvfeatured-videos-for-genesis
Data Attributes
name="_gfv_video_url"value="<?php echo $url; ?>"
Shortcode Output
[video height=
FAQ

Frequently Asked Questions about Genesis Featured Video