Gumlet Video Security & Risk Analysis

wordpress.org/plugins/gumlet-video

An official plugin by Gumlet for video embedding, dynamic watermark configuration, user level analytics and shortcode.

200 active installs v1.2.0 PHP 7.2+ WP 5.0+ Updated Nov 20, 2025
content-securitydymanic-watermarkingvideo-embed
99
A · Safe
CVEs total1
Unpatched0
Last CVEFeb 17, 2025
Safety Verdict

Is Gumlet Video Safe to Use in 2026?

Generally Safe

Score 99/100

Gumlet Video has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Feb 17, 2025Updated 4mo ago
Risk Assessment

The "gumlet-video" v1.2.0 plugin demonstrates a generally good security posture based on the static analysis. The absence of dangerous functions, proper output escaping for all outputs, and the exclusive use of prepared statements for SQL queries are commendable practices. The plugin also appears to have a limited attack surface with no unprotected entry points. However, the static analysis does reveal potential areas for improvement. Specifically, the absence of any nonce checks or capability checks on its single shortcode is a significant concern, as this could allow for unauthorized actions if the shortcode is vulnerable. Furthermore, the plugin has a history of a medium-severity Cross-Site Scripting (XSS) vulnerability, even though it is currently patched. This historical pattern suggests a past weakness in input sanitization or output encoding, which warrants continued vigilance.

Key Concerns

  • Shortcode lacks nonce and capability checks
  • History of medium severity XSS vulnerability
Vulnerabilities
1

Gumlet Video Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-13576medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Gumlet Video <= 1.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

Feb 17, 2025 Patched in 1.0.4 (2d)
Code Analysis
Analyzed Mar 16, 2026

Gumlet Video Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
24 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped24 total outputs
Attack Surface

Gumlet Video Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[gumlet] gumlet-video.php:140
WordPress Hooks 6
filterplugin_action_linksgumlet-video.php:153
actioninitgumlet-video.php:157
actioninitgumlet-video.php:186
actionadmin_initincludes\video-options.php:25
actionadmin_menuincludes\video-options.php:26
actionadmin_initincludes\video-options.php:27
Maintenance & Trust

Gumlet Video Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 20, 2025
PHP min version7.2
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs200
Developer Profile

Gumlet Video Developer Profile

adityapatadia

2 plugins · 800 total installs

100
trust score
Avg Security Score
100/100
Avg Patch Time
2 days
View full developer profile
Detection Fingerprints

How We Detect Gumlet Video

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gumlet-video/includes/assets/css/gumlet-admin.css/wp-content/plugins/gumlet-video/includes/assets/js/gumlet-admin.js/wp-content/plugins/gumlet-video/blocks/gumlet-video-block/build/index.js/wp-content/plugins/gumlet-video/blocks/gumlet-video-block/build/style-index.css
Script Paths
/wp-content/plugins/gumlet-video/blocks/gumlet-video-block/build/index.js
Version Parameters
gumlet-video/includes/assets/css/gumlet-admin.css?ver=gumlet-video/includes/assets/js/gumlet-admin.js?ver=gumlet-video/blocks/gumlet-video-block/build/index.js?ver=gumlet-video/blocks/gumlet-video-block/build/style-index.css?ver=

HTML / DOM Fingerprints

CSS Classes
gumlet-video-block__editor--activegumlet-video-block__player--active
HTML Comments
<!-- Generated by Gumlet Video Plugin -->
Data Attributes
data-gumlet-video-id
JS Globals
window.gumletVideoSettings
Shortcode Output
<iframe src="https://play.gumlet.io/embed/loading="lazy" title="Gumlet video player"
FAQ

Frequently Asked Questions about Gumlet Video