Inventive stock player Security & Risk Analysis

wordpress.org/plugins/inventive-stock-player-lite

This free wordpress plugin is created for videomakers and musician which have their video and audioproject on different music libraries and need to ha …

10 active installs v0.11 PHP + WP 3.8+ Updated Jun 10, 2015
audio-playercool-playermp3-playerspectrum-analyzervideo-player
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Inventive stock player Safe to Use in 2026?

Generally Safe

Score 85/100

Inventive stock player has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The "inventive-stock-player-lite" v0.11 plugin exhibits a mixed security posture. On the positive side, there are no known CVEs, the plugin utilizes prepared statements for all SQL queries, and the attack surface appears to be zero in terms of publicly exposed AJAX handlers, REST API routes, shortcodes, and cron events without proper authorization. This suggests a deliberate effort to minimize direct entry points for attackers.

However, significant concerns arise from the static analysis. The low percentage of properly escaped output (22%) indicates a high likelihood of Cross-Site Scripting (XSS) vulnerabilities, as data is not being sufficiently sanitized before being displayed to users. The presence of unsanitized paths in the taint analysis, even if not classified as critical or high severity in this limited analysis, suggests potential for path traversal or file inclusion vulnerabilities. The lack of nonce checks on any potential entry points, combined with only one capability check across the entire codebase, means that even if entry points were discovered, authorization checks might be insufficient.

The complete absence of recorded vulnerabilities in its history is a positive sign, but it should not be interpreted as a guarantee of future security. The current findings, particularly the poor output escaping and the taint flow indicating unsanitized paths, present tangible risks that need to be addressed. The plugin has strengths in its limited attack surface and SQL handling but exhibits significant weaknesses in output sanitization and potentially in authorization, warranting a cautious approach.

Key Concerns

  • Low output escaping percentage
  • Unsanitized paths in taint analysis
  • No nonce checks
  • Only one capability check
Vulnerabilities
None known

Inventive stock player Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Inventive stock player Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
35
10 escaped
Nonce Checks
0
Capability Checks
1
File Operations
6
External Requests
1
Bundled Libraries
0

Output Escaping

22% escaped45 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<general-options> (admin\general-options.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Inventive stock player Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 17
filterwp_audio_shortcode_overrideinc\filters.php:20
filterwp_audio_extensionsinc\filters.php:25
filterwp_audio_shortcodeinc\filters.php:38
filterpost_thumbnail_htmlinc\filters.php:53
filterthe_titleinc\filters.php:96
filterthe_contentinc\filters.php:124
filterthe_titleinc\filters.php:127
filterwoocommerce_loop_add_to_cart_linkinc\filters.php:150
actionwidgets_initinc\widget.php:144
actioninitinventive-stock-audio-video-player.php:25
actionadmin_enqueue_scriptsinventive-stock-audio-video-player.php:39
actionwp_enqueue_scriptsinventive-stock-audio-video-player.php:50
actionadmin_enqueue_scriptsinventive-stock-audio-video-player.php:55
filterwp_mediaelement_fallbackinventive-stock-audio-video-player.php:80
actionadmin_menuinventive-stock-audio-video-player.php:85
actionwp_footerinventive-stock-audio-video-player.php:140
actionwp_enqueue_scriptsinventive-stock-audio-video-player.php:143
Maintenance & Trust

Inventive stock player Maintenance & Trust

Maintenance Signals

WordPress version tested4.3.34
Last updatedJun 10, 2015
PHP min version
Downloads2K

Community Trust

Rating20/100
Number of ratings1
Active installs10
Developer Profile

Inventive stock player Developer Profile

inventive3d

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Inventive stock player

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/inventive-stock-player-lite/style.css/wp-content/plugins/inventive-stock-player-lite/js/scripts.js/wp-content/plugins/inventive-stock-player-lite/js/admin_scripts.js
Script Paths
js/scripts.jsjs/admin_scripts.js/js/wp-mediaelement.js

HTML / DOM Fingerprints

CSS Classes
inventive_stock_audio_spectrum
HTML Comments
<!-- Plugin Name: Inventive stock video and audio player - lite Plugin URI: http://www.inventive3d.com Description: This free wordpress plugin is created for videomakers and musician which have their video and audioproject on different music libraries and need to have an unique video/audio player for their wordpress site. Just paste the link from your favourite library and magically it will be played inside your wordpress website with the default wp audio player. You can also add a buy link in post and woocommerce products. There is support for: audiojungle, pond5, videohive, luckstock, soundcloud. It extends wordpress audio/video shortocode, plus there is a cool spectrum analyzer for audio! Plugin offers these features in posts/products, a widget and a shortcode. In the lite version you can use the only the widget. Author: Francesco Puglisi - Inventive 3d Author URI: http://www.inventive3d.com/ Version: 0.11 Text Domain: inventive-stock-video-audio-player-lite Domain Path: / License: GNU General Public License v2 or later License URI: http://www.gnu.org/licenses/gpl-2.0.html ------------------------------------------------------------------------------------------------------------------>/* * Written by Francesco Puglisi <info@inventive3d.com>, June 2015 */
Data Attributes
id="analyser_render"
JS Globals
inventive_stock_player_bars_colorinventive_stock_player_bars_numberinventive_stock_player_bars_widthinventive_stock_player_bars_distance
FAQ

Frequently Asked Questions about Inventive stock player