
Video Gallery by Huzzaz Security & Risk Analysis
wordpress.org/plugins/huzzaz-video-galleryCreate a beautiful video gallery with YouTube, Vimeo, Facebook, and Twitch videos. It looks great on mobile, tablet, or desktop screens and it support …
Is Video Gallery by Huzzaz Safe to Use in 2026?
Use With Caution
Score 63/100Video Gallery by Huzzaz has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "huzzaz-video-gallery" plugin version 10.5 exhibits a mixed security posture. On the positive side, static analysis reveals strong adherence to secure coding practices, with no identified dangerous functions, all SQL queries using prepared statements, and all output properly escaped. There are also no file operations or external HTTP requests, and the attack surface through AJAX and REST API is well-protected. However, a significant concern arises from the presence of one unpatched medium severity vulnerability related to Cross-Site Scripting (XSS). The fact that this vulnerability is dated 2025-09-30 and is still listed as unpatched is a critical red flag, indicating a lack of prompt security patching by the developers.
While the current codebase appears robust in terms of preventing common vulnerabilities like SQL injection and XSS through proper sanitization and escaping, the historical unpatched vulnerability overshadows these strengths. The absence of nonce checks and capability checks on the single identified shortcode, while not immediately exploitable without further context or a specific vulnerability within the shortcode itself, represents a potential weak point that could be leveraged in conjunction with other vulnerabilities. The vulnerability history strongly suggests a pattern of past security issues that may not have been addressed in a timely manner, which could indicate a broader tendency towards slower security response. Therefore, while the current static analysis results are promising, the unpatched CVE presents a clear and present danger that necessitates immediate attention.
Key Concerns
- Unpatched Medium Severity CVE
- Missing Nonce Checks on Entry Point
- Missing Capability Checks on Entry Point
Video Gallery by Huzzaz Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Video Gallery by Huzzaz <= 10.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
Video Gallery by Huzzaz Code Analysis
Output Escaping
Video Gallery by Huzzaz Attack Surface
Shortcodes 1
Maintenance & Trust
Video Gallery by Huzzaz Maintenance & Trust
Maintenance Signals
Community Trust
Video Gallery by Huzzaz Alternatives
Video Gallery Block – Display your videos as a gallery in a professional way
video-gallery-block
Video Gallery Block lets you create responsive YouTube, Vimeo, and HTML5 video galleries with grid layouts, filters, and lightbox in Gutenberg.
Video gallery and Player
html5-videogallery-plus-player
Easy to add and display your HTML5, YouTube, Vimeo vedio gallery with Magnific Popup to your website. Also work with Gutenberg shortcode block.
Vidplex – Ultimate Video Gallery Block for YouTube in Gutenberg
vidplex
YouTube gallery plugin for WordPress – display channel videos or with video link/URL in responsive sliders, galleries, and featured layouts.
Modula Image Gallery – Photo Grid & Video Gallery
modula-best-grid-gallery
Create responsive image galleries with drag-and-drop grid builder. Custom layouts, video support, AI optimization. Works with any theme.
Mixed Media Gallery Blocks
simply-gallery-block
Create mixed media galleries with images, HTML5 video, YouTube, Vimeo, and VideoPress — all in one gallery by Simply Gallery.
Video Gallery by Huzzaz Developer Profile
1 plugin · 1K total installs
How We Detect Video Gallery by Huzzaz
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/huzzaz-video-gallery/js/hzframe.min.js/wp-content/plugins/huzzaz-video-gallery/js/hzframe_float.min.jshttps://huzzaz.com/js/hzframe.jshttps://huzzaz.com/js/hzframe.min.jshttps://huzzaz.com/js/hzframe_float.min.jsHTML / DOM Fingerprints
huzzazWrapperhzloadhzframehzfloatdata-id<div class="huzzazWrapper"><div class="hzload" style="width: 200px; padding: 10px; border-radius: 5px; margin: auto; text-align: center; background-color: #fff;"><img src="//huzzaz.com/images/hzload<iframe class="hzframe" src="<script src="https://huzzaz.com/js/hzframe.js"></script><style>.hzframe{transition: width .2s ease-in-out, height .2s ease-in-out, transform .38s ease-in-out;}.hzframe.hzfloat{position: fixed;