
Flowplayer Video Player Security & Risk Analysis
wordpress.org/plugins/flowplayer6-video-playerAdd a video file to WordPress with Flowplayer style. Embed a self-hosted, external or HTML5 compatible responsive video into a page with flowplayer.
Is Flowplayer Video Player Safe to Use in 2026?
Generally Safe
Score 85/100Flowplayer Video Player has a strong security track record. Known vulnerabilities have been patched promptly.
The 'flowplayer6-video-player' v1.0.5 plugin exhibits a mixed security posture. On the positive side, the static analysis reveals no dangerous functions, no raw SQL queries, and no file operations or external HTTP requests. Furthermore, the absence of critical or high-severity taint flows and the fact that all known vulnerabilities are patched contribute to a generally favorable impression.
However, several areas raise concerns. The plugin has a medium-severity Cross-Site Scripting (XSS) vulnerability recorded from November 2022, which, although patched, indicates a historical weakness in input sanitization or output escaping. The static analysis reveals that only 57% of output is properly escaped, leaving room for potential XSS attacks if unsanitized data is processed by the remaining outputs. Additionally, the complete lack of nonce checks and capability checks across all entry points (including the single shortcode) is a significant weakness. While the attack surface is small and currently appears to have no unprotected entry points, this lack of authorization and validation on the shortcode handler makes it susceptible to unauthorized execution if an attacker can trigger it.
In conclusion, while the plugin has addressed its past vulnerabilities and avoids many common pitfalls, the insufficient output escaping and the complete absence of nonce and capability checks on its shortcode handler represent notable security weaknesses that warrant attention. The presence of a past XSS vulnerability, even if patched, combined with these remaining issues, suggests a need for continued vigilance and potential remediation.
Key Concerns
- Medium severity XSS vulnerability history
- Significant percentage of unescaped output
- Missing nonce checks on shortcode
- Missing capability checks on shortcode
Flowplayer Video Player Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Flowerplayer Video Player <= 1.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
Flowplayer Video Player Code Analysis
Output Escaping
Flowplayer Video Player Attack Surface
Shortcodes 1
WordPress Hooks 8
Maintenance & Trust
Flowplayer Video Player Maintenance & Trust
Maintenance Signals
Community Trust
Flowplayer Video Player Alternatives
FV Flowplayer Video Player
fv-wordpress-flowplayer
WordPress's most reliable, easy to use and feature-rich video player. Supports responsive design, HTML5, playlists, ads, stats, Vimeo and YouTube.
Easy Video Player
easy-video-player
Easy Video Player is a WordPress video player that allows you to add videos to your WordPress site.
Videojs HTML5 Player
videojs-html5-player
Embed video file beautifully in WordPress using Video.js HTML5 Player. Embed HTML5 compatible responsive video in your post/page with Video.js.
FV Player 8
fv-player
WordPress's most reliable, easy to use and feature-rich video player. Supports playlists, ads, stats and user video position saving.
oEmbed External Video
oembed-external-video
oEmbed External Video plugin converts any external mp4 url into HTML5 video tag
Flowplayer Video Player Developer Profile
25 plugins · 157K total installs
How We Detect Flowplayer Video Player
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/flowplayer6-video-player/lib/flowplayer.min.js/wp-content/plugins/flowplayer6-video-player/lib/skin/skin.cssflowplayer6-video-player/lib/flowplayer.min.jsHTML / DOM Fingerprints
flowplayerminimalistfunctionalplayful<!-- This content is generated with the Flowplayer Video Player plugin --><!-- Flowplayer Video Player plugin -->data-ratiodata-shareflowplayer.conf.embedflowplayer.conf.keyboard<div id="fpdata-ratio="class="flowplayerbackground-size: 100%;