Video Gallery by Huzzaz Security & Risk Analysis

wordpress.org/plugins/huzzaz-video-gallery

Create a beautiful video gallery with YouTube, Vimeo, Facebook, and Twitch videos. It looks great on mobile, tablet, or desktop screens and it support …

1K active installs v10.5 PHP + WP 3.0.1+ Updated Nov 27, 2022
facebook-live-videofacebook-videovideo-galleryvimeo-video-galleryyoutube-video-gallery
63
C · Use Caution
CVEs total1
Unpatched1
Last CVESep 30, 2025
Safety Verdict

Is Video Gallery by Huzzaz Safe to Use in 2026?

Use With Caution

Score 63/100

Video Gallery by Huzzaz has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Sep 30, 2025Updated 3yr ago
Risk Assessment

The "huzzaz-video-gallery" plugin version 10.5 exhibits a mixed security posture. On the positive side, static analysis reveals strong adherence to secure coding practices, with no identified dangerous functions, all SQL queries using prepared statements, and all output properly escaped. There are also no file operations or external HTTP requests, and the attack surface through AJAX and REST API is well-protected. However, a significant concern arises from the presence of one unpatched medium severity vulnerability related to Cross-Site Scripting (XSS). The fact that this vulnerability is dated 2025-09-30 and is still listed as unpatched is a critical red flag, indicating a lack of prompt security patching by the developers.

While the current codebase appears robust in terms of preventing common vulnerabilities like SQL injection and XSS through proper sanitization and escaping, the historical unpatched vulnerability overshadows these strengths. The absence of nonce checks and capability checks on the single identified shortcode, while not immediately exploitable without further context or a specific vulnerability within the shortcode itself, represents a potential weak point that could be leveraged in conjunction with other vulnerabilities. The vulnerability history strongly suggests a pattern of past security issues that may not have been addressed in a timely manner, which could indicate a broader tendency towards slower security response. Therefore, while the current static analysis results are promising, the unpatched CVE presents a clear and present danger that necessitates immediate attention.

Key Concerns

  • Unpatched Medium Severity CVE
  • Missing Nonce Checks on Entry Point
  • Missing Capability Checks on Entry Point
Vulnerabilities
1

Video Gallery by Huzzaz Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-62910medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Video Gallery by Huzzaz <= 10.5 - Authenticated (Contributor+) Stored Cross-Site Scripting

Sep 30, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

Video Gallery by Huzzaz Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
9 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped9 total outputs
Attack Surface

Video Gallery by Huzzaz Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[huzzaz] huzzaz.php:97
Maintenance & Trust

Video Gallery by Huzzaz Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedNov 27, 2022
PHP min version
Downloads136K

Community Trust

Rating88/100
Number of ratings44
Active installs1K
Developer Profile

Video Gallery by Huzzaz Developer Profile

deshine

1 plugin · 1K total installs

68
trust score
Avg Security Score
63/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Video Gallery by Huzzaz

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/huzzaz-video-gallery/js/hzframe.min.js/wp-content/plugins/huzzaz-video-gallery/js/hzframe_float.min.js
Script Paths
https://huzzaz.com/js/hzframe.jshttps://huzzaz.com/js/hzframe.min.jshttps://huzzaz.com/js/hzframe_float.min.js

HTML / DOM Fingerprints

CSS Classes
huzzazWrapperhzloadhzframehzfloat
Data Attributes
data-id
Shortcode Output
<div class="huzzazWrapper"><div class="hzload" style="width: 200px; padding: 10px; border-radius: 5px; margin: auto; text-align: center; background-color: #fff;"><img src="//huzzaz.com/images/hzload<iframe class="hzframe" src="<script src="https://huzzaz.com/js/hzframe.js"></script><style>.hzframe{transition: width .2s ease-in-out, height .2s ease-in-out, transform .38s ease-in-out;}.hzframe.hzfloat{position: fixed;
FAQ

Frequently Asked Questions about Video Gallery by Huzzaz