Mowplayer Security & Risk Analysis

wordpress.org/plugins/mowplayer

Easily intract with mowplayer videos and get player inserted in your page in a few clicks.

10 active installs v5.1.6 PHP + WP 3.0+ Updated May 13, 2021
monetizationmowplayervideo-ads
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Mowplayer Safe to Use in 2026?

Generally Safe

Score 85/100

Mowplayer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The "mowplayer" plugin v5.1.6 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of known CVEs and the plugin's limited attack surface with no unprotected entry points are positive indicators. The code shows a good practice of utilizing prepared statements for a high percentage of its SQL queries, and it includes capability checks, which are essential for restricting access to sensitive functionalities. The inclusion of TinyMCE, a widely used and generally secure library, is also a neutral factor.

However, there are significant areas of concern that detract from its overall security. The most critical finding is that 0% of output is properly escaped, presenting a high risk of Cross-Site Scripting (XSS) vulnerabilities. With three identified output points, every instance where the plugin outputs data to the user interface is potentially vulnerable. Furthermore, the plugin performs seven file operations without clear indications of sanitization or authentication checks on these operations, which could lead to arbitrary file access or manipulation if not handled carefully. The complete lack of nonce checks, especially in conjunction with file operations and the shortcode entry point, is also a notable weakness that could facilitate CSRF attacks.

In conclusion, while "mowplayer" v5.1.6 benefits from a clean vulnerability history and a controlled attack surface, the severe lack of output escaping and the absence of nonce checks are critical security flaws. These weaknesses, coupled with potential risks associated with file operations, mean that despite its good track record, the plugin requires immediate attention to address the identified security holes to prevent potential exploitation.

Key Concerns

  • 0% output escaping
  • No nonce checks
  • File operations without clear security context
Vulnerabilities
None known

Mowplayer Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Mowplayer Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
7 prepared
Unescaped Output
3
0 escaped
Nonce Checks
0
Capability Checks
2
File Operations
7
External Requests
2
Bundled Libraries
1

Bundled Libraries

TinyMCE

SQL Query Safety

88% prepared8 total queries

Output Escaping

0% escaped3 total outputs
Attack Surface

Mowplayer Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[Mowplayer-Video] mow.php:333
WordPress Hooks 12
filtercontent_save_prebkp-functions.php:118
filtercontent_save_prefunctions.php:89
actionget_ads_filterfunctions.php:151
actionadmin_enqueue_scriptsmow.php:71
actionadmin_menumow.php:72
actionadmin_enqueue_scriptsmow.php:77
actionadmin_headmow.php:78
filtermce_external_pluginsmow.php:97
filtermce_buttonsmow.php:98
actionenqueue_block_editor_assetsmow.php:118
actionwp_headmow.php:158
actionwp_headmow.php:170
Maintenance & Trust

Mowplayer Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedMay 13, 2021
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Mowplayer Developer Profile

supportmowplayer

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Mowplayer

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mowplayer/css/mowplayer.css/wp-content/plugins/mowplayer/js/custom-tinymce.js/wp-content/plugins/mowplayer/js/custom-block-editor.js/wp-content/plugins/mowplayer/css/custom-block-editor.css
Script Paths
/wp-content/plugins/mowplayer/js/custom-tinymce.js/wp-content/plugins/mowplayer/js/custom-block-editor.js
Version Parameters
mowplayer/css/mowplayer.css?ver=mowplayer/js/custom-tinymce.js?ver=mowplayer/js/custom-block-editor.js?ver=mowplayer/css/custom-block-editor.css?ver=

HTML / DOM Fingerprints

Data Attributes
data-mow_video
JS Globals
WPURLS
Shortcode Output
<script src="//mowplayer.com/watch/js/v-<div data-mow_video="v-<amp-iframedata-mediaid=v-
FAQ

Frequently Asked Questions about Mowplayer