
Video Short Code Security & Risk Analysis
wordpress.org/plugins/insert-video-with-shortcodeThis plugin only for some chinese video site.
Is Video Short Code Safe to Use in 2026?
Generally Safe
Score 85/100Video Short Code has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "insert-video-with-shortcode" v1.2.0 exhibits a mixed security posture. On the positive side, it has no recorded vulnerabilities in its history, uses prepared statements for all SQL queries, and has no external HTTP requests or dangerous function calls. It also avoids common pitfalls like bundled outdated libraries.
However, there are significant concerns arising from the static analysis. The complete lack of capability checks and nonce checks across all entry points, including its 8 shortcodes, is a major security weakness. Furthermore, 100% of its output is not properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. The single file operation also warrants closer inspection as it could be a potential vector for abuse if not handled securely. While taint analysis shows no flows, this could be due to the limited scope of analysis or the simplicity of the code, and doesn't negate the risks from other identified issues.
In conclusion, while the plugin benefits from a clean vulnerability history and secure SQL practices, the absence of critical security checks like capability and nonce validation, coupled with widespread unescaped output, presents a substantial risk of exploitation. The current version is not recommended for production environments without significant remediation of these identified vulnerabilities.
Key Concerns
- 0% output escaping
- 0 capability checks
- 0 nonce checks
- 1 file operation
Video Short Code Security Vulnerabilities
Video Short Code Code Analysis
Output Escaping
Video Short Code Attack Surface
Shortcodes 8
WordPress Hooks 2
Maintenance & Trust
Video Short Code Maintenance & Trust
Maintenance Signals
Community Trust
Video Short Code Alternatives
WP Youku
wp-youku
用这个插件,直接输入优酷视频的链接,就行了!
XML Sitemap Generator for Google
google-sitemap-generator
Generate multiple types of sitemaps to improve SEO and get your website indexed quickly.
Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider
ml-slider
Slider, gallery, carousel plugin for WordPress. Build your image slider, video slider, post slider, YouTube slider, or WooCommerce product slider.
Prime Slider – Addons for Elementor
bdthemes-prime-slider-lite
Create responsive sliders using Elementor for hero sections, posts, logos, images, products, testimonials, and more.
Modula Image Gallery – Photo Grid & Video Gallery
modula-best-grid-gallery
Create responsive image galleries with drag-and-drop grid builder. Custom layouts, video support, AI optimization. Works with any theme.
Video Short Code Developer Profile
2 plugins · 20 total installs
How We Detect Video Short Code
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
insert-video-with-shortcode/style.css?ver=insert-video-with-shortcode/script.js?ver=HTML / DOM Fingerprints
<iframe height="{height}" width="{width}" src="http://player.youku.com/embed/{code}" frameborder=0 allowfullscreen></iframe><object width="{width}" height="{height}" type="application/x-shockwave-flash" data="http://www.tudou.com/a/{code}/v.swf"><param name="quality" value="high"><param name="allowScriptAccess" value="always"><param name="flashvars" value="playMovie=true&isAutoPlay=true"></object><object width="{width}" height="{height}" type="application/x-shockwave-flash" data="http://player.ku6.com/refer/{code}/v.swf"><param name="quality" value="high"><param name="allowScriptAccess" value="always"><param name="flashvars" value="playMovie=true&isAutoPlay=true"></object><object width="{width}" height="{height}" type="application/x-shockwave-flash" data="http://share.vrs.sohu.com/{code}/v.swf&topBar=1&autoplay=false&pub_catecode=0&from=page"><param name="quality" value="high"><param name="allowScriptAccess" value="always"><param name="flashvars" value="playMovie=true&isAutoPlay=true"></object>