Insert Video with Schema.org (IVS) Security & Risk Analysis

wordpress.org/plugins/insert-video-with-schemaorg-ivws

Plugin created shortcode to insert YouTube videos with microdate on Schema.org for rich snippet

300 active installs v3.1.7 PHP 5.6+ WP 4.0+ Updated Nov 14, 2018
schema-orgschemaorgshortcodeshortcodesyoutube-shortcode
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Insert Video with Schema.org (IVS) Safe to Use in 2026?

Generally Safe

Score 85/100

Insert Video with Schema.org (IVS) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The plugin 'insert-video-with-schemaorg-ivws' v3.1.7 demonstrates a strong security posture based on the provided static analysis. The code adheres to excellent security practices, evidenced by the absence of dangerous functions, 100% use of prepared statements for SQL queries, and complete output escaping. Crucially, there are no observed taint flows or unsanitized paths, indicating a low risk of common injection vulnerabilities. The plugin also correctly implements capability checks and avoids file operations or external HTTP requests, further reducing its attack surface. The vulnerability history is also clear, with no recorded CVEs, which suggests a history of secure development and maintenance.

However, a notable area for improvement is the absence of nonce checks. While the current data indicates no unprotected entry points and robust capability checks are present, the lack of nonces on any potential entry points, even if currently secured by capability checks, represents a potential weakness. In scenarios where capability checks might be bypassed or misconfigured in the future, the absence of nonces could leave the plugin vulnerable to CSRF attacks. The presence of a shortcode as an entry point, while currently protected, could be a point of future concern if not carefully managed.

In conclusion, the plugin is fundamentally secure with robust coding practices, particularly around data handling and output. The primary concern is the missing nonce checks, which is a standard security measure for protecting against CSRF. Addressing this would significantly enhance the plugin's overall security. The lack of past vulnerabilities is a very positive sign, but it's important to maintain vigilance and implement all best practices.

Key Concerns

  • Missing nonce checks
Vulnerabilities
None known

Insert Video with Schema.org (IVS) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Insert Video with Schema.org (IVS) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
12 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

TinyMCE

Output Escaping

100% escaped12 total outputs
Attack Surface

Insert Video with Schema.org (IVS) Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[art_yt] art-insert-video.php:166
WordPress Hooks 7
actionadmin_headadmin\tinymce.php:9
filtermce_external_pluginsadmin\tinymce.php:16
filtermce_buttonsadmin\tinymce.php:17
actionplugins_loadedart-insert-video.php:45
filtermce_external_languagesart-insert-video.php:53
actionwp_enqueue_scriptsart-insert-video.php:64
actionadmin_enqueue_scriptsart-insert-video.php:73
Maintenance & Trust

Insert Video with Schema.org (IVS) Maintenance & Trust

Maintenance Signals

WordPress version tested5.0.25
Last updatedNov 14, 2018
PHP min version5.6
Downloads5K

Community Trust

Rating100/100
Number of ratings3
Active installs300
Developer Profile

Insert Video with Schema.org (IVS) Developer Profile

Artem Abramovich

3 plugins · 5K total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Insert Video with Schema.org (IVS)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/insert-video-with-schemaorg-ivws/assets/css/style.css/wp-content/plugins/insert-video-with-schemaorg-ivws/assets/css/admin-style.css
Version Parameters
insert-video-with-schemaorg-ivws/assets/css/style.css?ver=jqueryui?ver=insert-video-with-schemaorg-ivws/assets/css/admin-style.css?ver=

HTML / DOM Fingerprints

CSS Classes
art_yt
Data Attributes
itemscopeitemiditemtypeitempropcontent
Shortcode Output
<div class="art_yt itemscope itemtype="http://schema.org/VideoObject"><link itemprop="url"<meta itemprop="name"
FAQ

Frequently Asked Questions about Insert Video with Schema.org (IVS)