Lazy load videos and sticky control Security & Risk Analysis

wordpress.org/plugins/lazy-load-videos-and-sticky-control

Lazy load and sticky your video. Super-easy and fun!

100 active installs v3.0.1 PHP 7.2+ WP 5.2+ Updated Nov 21, 2024
floating-videolazyloadshortcodesticky-videovideos
71
B · Generally Safe
CVEs total1
Unpatched1
Last CVENov 20, 2024
Download
Safety Verdict

Is Lazy load videos and sticky control Safe to Use in 2026?

Mostly Safe

Score 71/100

Lazy load videos and sticky control is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved. Keep it updated.

1 known CVE 1 unpatched Last CVE: Nov 20, 2024Updated 1yr ago
Risk Assessment

The plugin 'lazy-load-videos-and-sticky-control' v3.0.1 exhibits a mixed security posture. On the positive side, the static analysis reveals strong adherence to secure coding practices. There are no identified dangerous functions, all SQL queries utilize prepared statements, and all output is properly escaped. File operations and external HTTP requests are also absent, and the plugin implements nonce and capability checks for its entry points. The limited attack surface, consisting of a single shortcode with no apparent authentication bypass, is also a good sign.

However, a significant concern arises from the plugin's vulnerability history. The presence of one unpatched medium-severity CVE for Cross-Site Scripting (XSS) is a critical red flag. This indicates that despite good general coding practices, a specific vulnerability exists and is currently exploitable. The fact that the last vulnerability was recent (November 20, 2024) suggests ongoing issues or a lack of timely patching. The absence of taint analysis results in this report does not negate the proven existence of past vulnerabilities.

In conclusion, while the plugin demonstrates good security fundamentals in its current codebase, the unpatched XSS vulnerability creates a significant risk. Users should be aware that a known exploit exists. The plugin's strengths lie in its well-handled database operations and output escaping, but its weakness is the single, exploitable, unpatched vulnerability. Prioritizing the patching of this CVE is paramount for mitigating the identified risk.

Key Concerns

  • Unpatched Medium Severity CVE
Vulnerabilities
1

Lazy load videos and sticky control Security Vulnerabilities

CVEs by Year

1 CVE in 2024 · unpatched
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-11428medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Lazy load videos and sticky control <= 3.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

Nov 20, 2024Unpatched
Code Analysis
Analyzed Mar 16, 2026

Lazy load videos and sticky control Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
55 escaped
Nonce Checks
2
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

TinyMCE

Output Escaping

100% escaped55 total outputs
Attack Surface

Lazy load videos and sticky control Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[lazy-load-videos-and-sticky-control] inc\classes\class-lazy-load-videos-and-sticky-control-shortcode.php:81
WordPress Hooks 2
actionadmin_enqueue_scriptsinc\classes\helpers\class-settings-api.php:23
actionplugins_loadedlazy-load-videos-and-sticky-control.php:74
Maintenance & Trust

Lazy load videos and sticky control Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedNov 21, 2024
PHP min version7.2
Downloads5K

Community Trust

Rating84/100
Number of ratings5
Active installs100
Developer Profile

Lazy load videos and sticky control Developer Profile

Aishan

1 plugin · 100 total installs

74
trust score
Avg Security Score
71/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Lazy load videos and sticky control

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/lazy-load-videos-and-sticky-control/assets/js/llvasc-backend.min.js/wp-content/plugins/lazy-load-videos-and-sticky-control/assets/css/llvasc-frontend.css
Script Paths
/wp-content/plugins/lazy-load-videos-and-sticky-control/assets/js/llvasc-backend.min.js/wp-content/plugins/lazy-load-videos-and-sticky-control/assets/js/llvasc-frontend.js
Version Parameters
lazy-load-videos-and-sticky-control/assets/js/llvasc-backend.min.js?ver=lazy-load-videos-and-sticky-control/assets/css/llvasc-frontend.css?ver=lazy-load-videos-and-sticky-control/assets/js/llvasc-frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
llvasc-sticky-video
Data Attributes
data-llvasc-sticky
JS Globals
LLVSC_OPTIONS
FAQ

Frequently Asked Questions about Lazy load videos and sticky control