
MediaHaven – Video Gallery & HLS Player With YouTube & TikTok Security & Risk Analysis
wordpress.org/plugins/mediahaven-lite🚀 Performance & security-focused HLS & self-hosted video player. Powerful video gallery with YouTube & TikTok feeds, AJAX loading & setup wizard.
Is MediaHaven – Video Gallery & HLS Player With YouTube & TikTok Safe to Use in 2026?
Generally Safe
Score 100/100MediaHaven – Video Gallery & HLS Player With YouTube & TikTok has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The mediahaven-lite plugin v1.6.7 exhibits a mixed security posture. On the positive side, it demonstrates strong practices in its SQL query handling, utilizing prepared statements exclusively, and excellent output escaping with 99% of outputs properly handled. The absence of known CVEs and critical vulnerabilities in its history suggests a generally well-maintained codebase. However, a significant concern lies in its attack surface, particularly the 15 unprotected AJAX handlers. This represents a substantial entry point for potential attacks, as these handlers lack authentication checks. Furthermore, the taint analysis identified two flows with unsanitized paths, both categorized as high severity. While not critical, these flows could lead to vulnerabilities if exploited, especially when combined with the unprotected AJAX endpoints.
While the plugin has a clean vulnerability history, the presence of unprotected AJAX handlers and high-severity taint flows indicates areas that require immediate attention. The lack of authentication on a large portion of its AJAX endpoints is a direct invitation for abuse. The high-severity unsanitized path flows, though not yet exploited in public CVEs, are a clear indication of potential weaknesses that could be leveraged by an attacker. The plugin's strengths in SQL and output sanitization are commendable, but these are overshadowed by the significant risk posed by its exposed attack surface and identified taint issues. A balanced view suggests a plugin with some robust security implementations but critical gaps in its access control for its AJAX endpoints.
Key Concerns
- Unprotected AJAX handlers
- High severity taint flows with unsanitized paths
MediaHaven – Video Gallery & HLS Player With YouTube & TikTok Security Vulnerabilities
MediaHaven – Video Gallery & HLS Player With YouTube & TikTok Release Timeline
MediaHaven – Video Gallery & HLS Player With YouTube & TikTok Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
MediaHaven – Video Gallery & HLS Player With YouTube & TikTok Attack Surface
AJAX Handlers 19
Shortcodes 1
WordPress Hooks 69
Maintenance & Trust
MediaHaven – Video Gallery & HLS Player With YouTube & TikTok Maintenance & Trust
Maintenance Signals
Community Trust
MediaHaven – Video Gallery & HLS Player With YouTube & TikTok Alternatives
All-in-One Video Gallery
all-in-one-video-gallery
The ultimate video player & video gallery plugin for YouTubers, Video Bloggers, Course Creators, Podcasters, and anyone embedding videos on websites.
Instant Indexing for Google
fast-indexing-api
A very efficient yet simple plugin to take care of your indexing woos and helps get your content crawled by search bots instantly.
Feeds for YouTube (YouTube video, channel, and gallery plugin)
feeds-for-youtube
The Feeds for YouTube plugin allows you to display customizable YouTube feeds from any YouTube channel.
Modula Image Gallery – Photo Grid & Video Gallery
modula-best-grid-gallery
Create responsive image galleries with drag-and-drop grid builder. Custom layouts, video support, AI optimization. Works with any theme.
Embed Plus for YouTube Gallery, Livestream and Lazy Loading with Facades
youtube-embed-plus
A multi-featured plugin to embed YouTube in WordPress. Embed a video, YouTube channel gallery, playlist, or YouTube livestream. Defer JavaScript too!
MediaHaven – Video Gallery & HLS Player With YouTube & TikTok Developer Profile
1 plugin · 30 total installs
How We Detect MediaHaven – Video Gallery & HLS Player With YouTube & TikTok
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mediahaven-lite/assets/css/frontend/mediahaven-lite.css/wp-content/plugins/mediahaven-lite/assets/js/frontend/mediahaven-lite.js/wp-content/plugins/mediahaven-lite/assets/js/frontend/mediahaven-lite.jsmediahaven-lite/assets/css/frontend/mediahaven-lite.css?ver=mediahaven-lite/assets/js/frontend/mediahaven-lite.js?ver=HTML / DOM Fingerprints
wpnd-mediahaven-lite-containerwpnd-mediahaven-lite-video-player<!-- MediaHaven Lite Shortcode Start --><!-- MediaHaven Lite Shortcode End -->data-mh-lite-video-iddata-mh-lite-player-optionswindow.mediahavenLiteConfigvar mediahavenLiteSettings[mediahaven_lite_player][mediahaven_lite_gallery]