
Lazy Load for Videos Security & Risk Analysis
wordpress.org/plugins/lazy-load-for-videosBoost page speed by replacing embedded YouTube and Vimeo videos with a clickable preview image. Video scripts only load on click.
Is Lazy Load for Videos Safe to Use in 2026?
Generally Safe
Score 98/100Lazy Load for Videos has a strong security track record. Known vulnerabilities have been patched promptly.
The "lazy-load-for-videos" plugin v2.18.9 demonstrates some good security practices, such as using prepared statements for all SQL queries and performing nonce checks. However, a significant concern arises from its vulnerability history, which includes two medium-severity CVEs, specifically Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF). The fact that these vulnerabilities were present indicates a need for more robust input validation and output escaping, especially considering that only 62% of outputs are properly escaped. The absence of any critical or high-severity vulnerabilities in its history is positive, and the fact that there are currently no unpatched vulnerabilities is also reassuring. The plugin also has a remarkably small attack surface, with no apparent unprotected entry points, which is a strong positive security signal.
Key Concerns
- Medium severity CVEs in history (XSS, CSRF)
- Significant portion of outputs not properly escaped
- No capability checks implemented
Lazy Load for Videos Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Lazy Load for Videos <= 2.18.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via data-video-title and href Attributes
Lazy Load for Videos <= 2.18.2 - Cross-Site Request Forgery
Lazy Load for Videos Code Analysis
SQL Query Safety
Output Escaping
Lazy Load for Videos Attack Surface
WordPress Hooks 40
Maintenance & Trust
Lazy Load for Videos Maintenance & Trust
Maintenance Signals
Community Trust
Lazy Load for Videos Alternatives
WP YouTube Lyte
wp-youtube-lyte
High performance YouTube video, playlist and audio-only embeds which don't slow down your blog and offer optimal accessibility.
Simple Lazy Load Videos
simple-lazy-load-videos
Simple Lazy Load for embedded video from YouTube and Vimeo
Velocity – Video Lazy Loading for YouTube, Twitch and Vimeo
velocity
Improve website performance by lazy loading and customizing your YouTube, Vimeo, Twitch and SoundCloud media embeds.
YEP: Optimize YouTube Embeds
yep-youtube-embed
Short Description: Load YouTube videos faster by replacing iframes with a preview image; the video plays only when clicked play.
Better Core Video Embeds
better-core-video-embeds
A plugin which enhances the core embed block for Youtube, Daily Motion and Vimeo videos by not loading unnecessary scripts until they are needed.
Lazy Load for Videos Developer Profile
1 plugin · 10K total installs
How We Detect Lazy Load for Videos
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/lazy-load-for-videos/src/js/admin-settings.js/wp-content/plugins/lazy-load-for-videos/src/css/admin-settings.css/wp-content/plugins/lazy-load-for-videos/src/js/admin-settings.js/wp-content/plugins/lazy-load-for-videos/src/js/admin-settings.js?ver=/wp-content/plugins/lazy-load-for-videos/src/css/admin-settings.css?ver=HTML / DOM Fingerprints
llv-modal-video<!-- Plugin by Kevin Weber || www.kweber.com -->data-lazy-video-iddata-lazy-video-widthdata-lazy-video-heightdata-lazy-video-titledata-lazy-video-lazydata-lazy-video-typeKW_LLV_FrontendKW_LLV_Settings