Gutena Video Lightbox Security & Risk Analysis

wordpress.org/plugins/gutena-lightbox

Gutena Video Lightbox is a WordPress Block that allows you to add a video in a popup window that goes over the website content.

1K active installs v1.0.3 PHP 5.6+ WP 5.8+ Updated Dec 18, 2025
blocklightboxpopupvimeoyoutube
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Gutena Video Lightbox Safe to Use in 2026?

Generally Safe

Score 100/100

Gutena Video Lightbox has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The "gutena-lightbox" v1.0.3 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, a complete reliance on prepared statements for SQL queries, and 100% proper output escaping are significant strengths. Furthermore, the presence of nonce checks on all identified AJAX entry points is a positive indicator of security-conscious development. The plugin also has a clean vulnerability history with no known CVEs, which is a good sign of its past security performance.

However, the analysis also highlights a notable weakness: a complete lack of capability checks on its entry points. While nonce checks can prevent certain types of CSRF attacks, they do not ensure that the user performing the action has the necessary permissions. This could be a concern if the AJAX actions performed by the plugin are sensitive in nature. The absence of taint analysis results is also a neutral point, as it means no vulnerabilities were detected through that method, but it doesn't necessarily confirm their complete absence. The limited attack surface with only two AJAX handlers, both protected by nonces, is a mitigating factor for the lack of capability checks, but it remains an area for improvement.

In conclusion, "gutena-lightbox" v1.0.3 appears to be a relatively secure plugin due to its adherence to core security practices like prepared statements and output escaping, and its clean history. The primary area for concern is the missing capability checks on its AJAX actions, which, while not directly exploited based on the data, represents a potential security gap. The plugin's strengths outweigh its weaknesses in this analysis, but addressing the capability check gap would further solidify its security.

Key Concerns

  • Missing capability checks on entry points
Vulnerabilities
None known

Gutena Video Lightbox Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Gutena Video Lightbox Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
4 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped4 total outputs
Attack Surface

Gutena Video Lightbox Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_install_gutena_kit_pluginincludes\gutena\gutena-ecosys-onboard\gutena-ecosys-onboard.php:78
authwp_ajax_dismiss_gutena_kit_ctaincludes\gutena\gutena-ecosys-onboard\gutena-ecosys-onboard.php:81
WordPress Hooks 3
actioninitgutena-lightbox.php:64
filterblock_categories_allgutena-lightbox.php:65
actionenqueue_block_editor_assetsincludes\gutena\gutena-ecosys-onboard\gutena-ecosys-onboard.php:76
Maintenance & Trust

Gutena Video Lightbox Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 18, 2025
PHP min version5.6
Downloads11K

Community Trust

Rating0/100
Number of ratings0
Active installs1K
Developer Profile

Gutena Video Lightbox Developer Profile

Saad Iqbal

84 plugins · 1.4M total installs

76
trust score
Avg Security Score
96/100
Avg Patch Time
287 days
View full developer profile
Detection Fingerprints

How We Detect Gutena Video Lightbox

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gutena-lightbox/build/index.js/wp-content/plugins/gutena-lightbox/build/index.css
Script Paths
/wp-content/plugins/gutena-lightbox/build/index.js
Version Parameters
gutena-lightbox/build/index.css?ver=gutena-lightbox/build/index.js?ver=

HTML / DOM Fingerprints

CSS Classes
gutena-play-button-block-gutena-block-library-plugin-notice
HTML Comments
<!-- wp:gutena/play-button --><!-- /wp:gutena/play-button --><!-- wp:gutena-kit-blocks/plugin-notice --><!-- /wp:gutena-kit-blocks/plugin-notice -->
Data Attributes
data-gutena-kit-notice-dismissdata-gutena-kit-install-button
JS Globals
gutenaEcosysOnboardData
FAQ

Frequently Asked Questions about Gutena Video Lightbox