
Media Player Addons for Elementor – Audio and Video Widgets for Elementor Security & Risk Analysis
wordpress.org/plugins/media-player-addons-for-elementorExtend Elementor with powerful, customizable media players for audio, video, streaming & playlists.
Is Media Player Addons for Elementor – Audio and Video Widgets for Elementor Safe to Use in 2026?
Generally Safe
Score 99/100Media Player Addons for Elementor – Audio and Video Widgets for Elementor has a strong security track record. Known vulnerabilities have been patched promptly.
The security posture of the 'media-player-addons-for-elementor' plugin v1.1.3 appears to be generally strong, with no critical or high severity vulnerabilities identified in the static analysis or vulnerability history. The plugin demonstrates good practices by utilizing prepared statements for all SQL queries and having a high percentage of properly escaped output. Furthermore, the absence of file operations, external HTTP requests, and the presence of nonce and capability checks on its AJAX handlers contribute positively to its security.
However, there are a few areas that warrant attention. While the attack surface is small and appears to be protected by authentication, the fact that 3 AJAX handlers exist means there are potential entry points that require diligent verification. The vulnerability history, while currently clear, shows a past medium severity Cross-Site Scripting (XSS) vulnerability, indicating that robust input sanitization and output escaping are crucial for preventing future issues. The bundled Freemius library, while common, could also be a potential vector if it has known vulnerabilities in its version, though this is not explicitly stated in the provided data.
In conclusion, the plugin has a good foundation with secure coding practices in place for SQL and output handling. The lack of currently unpatched vulnerabilities is a positive sign. The primary risks lie in the continued vigilance required for the AJAX handlers and the potential for future vulnerabilities if past patterns of XSS are not thoroughly mitigated. The bundled library also presents a minor, unquantified risk.
Key Concerns
- Medium severity past vulnerability (XSS)
- Bundled library: Freemius v1.0 (potential for outdated)
- 3 AJAX handlers, requires strict auth checks
Media Player Addons for Elementor – Audio and Video Widgets for Elementor Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Media Player Addons for Elementor <= 1.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widget Fields
Media Player Addons for Elementor – Audio and Video Widgets for Elementor Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Media Player Addons for Elementor – Audio and Video Widgets for Elementor Attack Surface
AJAX Handlers 3
WordPress Hooks 19
Maintenance & Trust
Media Player Addons for Elementor – Audio and Video Widgets for Elementor Maintenance & Trust
Maintenance Signals
Community Trust
Media Player Addons for Elementor – Audio and Video Widgets for Elementor Alternatives
AutoCraft Player
autocraft-player
AutoCraft Player: The Ultimate Customizable Audio & Video Experience for WordPress
All-in-One Video Gallery
all-in-one-video-gallery
The ultimate video player & video gallery plugin for YouTubers, Video Bloggers, Course Creators, Podcasters, and anyone embedding videos on websites.
Wonder Video Embed
wonderplugin-video-embed
Embed MP4, Youtube, Vimeo, Wistia videos to the sidebar widget, WordPress posts and pages.
Lean Player – Video and Audio Player for WordPress, Elementor, Block Editor and Classic Editor
az-video-and-audio-player-addon-for-elementor
WordPress Video Player & Audio Player plugin - simple, lightweight and customizable HTML5, YouTube, Vimeo & mp3 media player that supports all devices
Video Gallery YouTube Vimeo
new-video-gallery
Create responsive YouTube and Vimeo video galleries with custom layouts, lightbox display, and easy shortcode embedding.
Media Player Addons for Elementor – Audio and Video Widgets for Elementor Developer Profile
120 plugins · 738K total installs
How We Detect Media Player Addons for Elementor – Audio and Video Widgets for Elementor
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/media-player-addons-for-elementor/assets/css/custom-style.css/wp-content/plugins/media-player-addons-for-elementor/assets/css/audio-widget.css/wp-content/plugins/media-player-addons-for-elementor/assets/css/video-widget.css/wp-content/plugins/media-player-addons-for-elementor/assets/css/video-playlist.css/wp-content/plugins/media-player-addons-for-elementor/assets/js/audio-widget.js/wp-content/plugins/media-player-addons-for-elementor/assets/js/video-widget.js/wp-content/plugins/media-player-addons-for-elementor/assets/js/video-playlist.js/wp-content/plugins/media-player-addons-for-elementor/assets/js/audio-widget.js/wp-content/plugins/media-player-addons-for-elementor/assets/js/video-widget.js/wp-content/plugins/media-player-addons-for-elementor/assets/js/video-playlist.jsmedia-player-addons-for-elementor/assets/css/custom-style.css?ver=media-player-addons-for-elementor/assets/css/audio-widget.css?ver=media-player-addons-for-elementor/assets/css/video-widget.css?ver=media-player-addons-for-elementor/assets/css/video-playlist.css?ver=media-player-addons-for-elementor/assets/js/audio-widget.js?ver=media-player-addons-for-elementor/assets/js/video-widget.js?ver=media-player-addons-for-elementor/assets/js/video-playlist.js?ver=HTML / DOM Fingerprints
audioplayeraudioplayer-containeraudioplayer-bodyvideo-player-wrapbpa-video-player-wrapbpa-video-player-wrap-innerbpa-video-playlist-wrapbpa-video-playlist-wrap-inner<!-- Plugin Name: Media Player Addons for Elementor – Audio and Video Widgets for Elementor --><!-- Plugin URI: https://elementoraddons.org/media-player-addons/ --><!-- Description: Collection of media players to plaback of various media files such as .mp3, .mp4, .flv, .m3u8, .ogg, YouTube, Vimeo and moe.... --><!-- Version: 1.1.3 -->+5 moredata-settingsBMPA_VERSIONBMPA_DIR_URLBMPA_DIR_PATHMPAFE_HAS_PROmpafe_fsbaddon_main_element