
Last Video Widget Security & Risk Analysis
wordpress.org/plugins/last-video-widgetA widget that displays the last post af a category and resize its video. Viper's Video Quicktags plugin needed.
Is Last Video Widget Safe to Use in 2026?
Generally Safe
Score 85/100Last Video Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "last-video-widget" plugin v0.1 exhibits a mixed security posture. On one hand, the absence of known CVEs and the use of prepared statements for SQL queries are positive indicators. The plugin also shows no external HTTP requests or file operations, reducing potential attack vectors. However, significant concerns arise from the code analysis. The presence of the "create_function" dangerous function is a notable risk, as it can be exploited for code injection if user input is not meticulously sanitized before being passed to it. Furthermore, the alarming statistic that 0% of its 16 outputs are properly escaped suggests a high likelihood of Cross-Site Scripting (XSS) vulnerabilities. The lack of nonce checks and capability checks on its entry points, although the entry points are currently zero, leaves it open to potential future expansion with unauthenticated actions if not handled carefully. The vulnerability history is clean, which is good, but doesn't negate the immediate risks identified in the code analysis, especially the lack of output escaping.
Key Concerns
- Dangerous function detected (create_function)
- Output escaping is not implemented
- No nonce checks on entry points
- No capability checks on entry points
Last Video Widget Security Vulnerabilities
Last Video Widget Code Analysis
Dangerous Functions Found
Output Escaping
Last Video Widget Attack Surface
WordPress Hooks 1
Maintenance & Trust
Last Video Widget Maintenance & Trust
Maintenance Signals
Community Trust
Last Video Widget Alternatives
No alternatives data available yet.
Last Video Widget Developer Profile
2 plugins · 50 total installs
How We Detect Last Video Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/last-video-widget/last-video-widget.phpHTML / DOM Fingerprints
Last_Video_Widgetid="last_video_widget-title"name="last_video_widget-title"id="last_video_widget-category"name="last_video_widget-category"id="last_video_widget-width"name="last_video_widget-width"[youtube width="