
Lazy load videos and sticky control Security & Risk Analysis
wordpress.org/plugins/lazy-load-videos-and-sticky-controlLazy load and sticky your video. Super-easy and fun!
Is Lazy load videos and sticky control Safe to Use in 2026?
Mostly Safe
Score 71/100Lazy load videos and sticky control is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved. Keep it updated.
The plugin 'lazy-load-videos-and-sticky-control' v3.0.1 exhibits a mixed security posture. On the positive side, the static analysis reveals strong adherence to secure coding practices. There are no identified dangerous functions, all SQL queries utilize prepared statements, and all output is properly escaped. File operations and external HTTP requests are also absent, and the plugin implements nonce and capability checks for its entry points. The limited attack surface, consisting of a single shortcode with no apparent authentication bypass, is also a good sign.
However, a significant concern arises from the plugin's vulnerability history. The presence of one unpatched medium-severity CVE for Cross-Site Scripting (XSS) is a critical red flag. This indicates that despite good general coding practices, a specific vulnerability exists and is currently exploitable. The fact that the last vulnerability was recent (November 20, 2024) suggests ongoing issues or a lack of timely patching. The absence of taint analysis results in this report does not negate the proven existence of past vulnerabilities.
In conclusion, while the plugin demonstrates good security fundamentals in its current codebase, the unpatched XSS vulnerability creates a significant risk. Users should be aware that a known exploit exists. The plugin's strengths lie in its well-handled database operations and output escaping, but its weakness is the single, exploitable, unpatched vulnerability. Prioritizing the patching of this CVE is paramount for mitigating the identified risk.
Key Concerns
- Unpatched Medium Severity CVE
Lazy load videos and sticky control Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Lazy load videos and sticky control <= 3.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
Lazy load videos and sticky control Code Analysis
Bundled Libraries
Output Escaping
Lazy load videos and sticky control Attack Surface
Shortcodes 1
WordPress Hooks 2
Maintenance & Trust
Lazy load videos and sticky control Maintenance & Trust
Maintenance Signals
Community Trust
Lazy load videos and sticky control Alternatives
Auto Last Youtube Video
auto-last-youtube-video
This plugin provides both Widget and Shortcode to show latest videos from any public Youtube channel.
Vimeo Everywhere
vimeo-everywhere
Display your public Vimeo videos on your WordPress website via shortcode, widget, or dashboard menu. Perfect for making a custom training library
Floating Video Widget
floating-video-widget
Add a customizable floating video widget to any page or post using a simple shortcode.
WP Shortcodes Plugin — Shortcodes Ultimate
shortcodes-ultimate
A comprehensive collection of visual components for your site
MW WP Form
mw-wp-form
MW WP Form is shortcode base contact form plugin. This plugin have many features. For example you can use many validation rules, inquiry data saving, …
Lazy load videos and sticky control Developer Profile
1 plugin · 100 total installs
How We Detect Lazy load videos and sticky control
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/lazy-load-videos-and-sticky-control/assets/js/llvasc-backend.min.js/wp-content/plugins/lazy-load-videos-and-sticky-control/assets/css/llvasc-frontend.css/wp-content/plugins/lazy-load-videos-and-sticky-control/assets/js/llvasc-backend.min.js/wp-content/plugins/lazy-load-videos-and-sticky-control/assets/js/llvasc-frontend.jslazy-load-videos-and-sticky-control/assets/js/llvasc-backend.min.js?ver=lazy-load-videos-and-sticky-control/assets/css/llvasc-frontend.css?ver=lazy-load-videos-and-sticky-control/assets/js/llvasc-frontend.js?ver=HTML / DOM Fingerprints
llvasc-sticky-videodata-llvasc-stickyLLVSC_OPTIONS