OS media – HTML5 Featured Video Security & Risk Analysis

wordpress.org/plugins/os-media

For Featured video contents based on the latest HTML5 Video-js library (5.2.1). It works with local & remote media, Amazon S3, Youtube & Vimeo …

10 active installs v2.3 PHP + WP + Updated Oct 16, 2016
featuredpagepoststreamingvideo
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is OS media – HTML5 Featured Video Safe to Use in 2026?

Generally Safe

Score 85/100

OS media – HTML5 Featured Video has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The "os-media" v2.3 plugin exhibits a generally good security posture based on the provided static analysis. The absence of known CVEs and a clean vulnerability history are positive indicators. The plugin also demonstrates good practices by using prepared statements for all SQL queries and appears to have a limited attack surface. However, there are notable areas for concern. A very low percentage of output is properly escaped, which represents a significant risk for cross-site scripting (XSS) vulnerabilities. While the total number of output points is high, the low escape rate means a large portion of these outputs could be vulnerable. Additionally, the lack of nonce checks across its entry points, particularly the single shortcode, is a critical weakness that could allow for cross-site request forgery (CSRF) attacks. The limited capability checks also contribute to potential unauthorized actions.

Key Concerns

  • Very low output escaping rate
  • No nonce checks on entry points
  • Limited capability checks
Vulnerabilities
None known

OS media – HTML5 Featured Video Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

OS media – HTML5 Featured Video Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
175
8 escaped
Nonce Checks
0
Capability Checks
3
File Operations
7
External Requests
2
Bundled Libraries
0

Output Escaping

4% escaped183 total outputs
Attack Surface

OS media – HTML5 Featured Video Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[youtube] classes\OSmedia-post-frontend.php:395
WordPress Hooks 22
actionadmin_noticesbootstrap.php:100
filterpre_get_postsclasses\CPT_columns.php:65
actionwpmu_new_blogclasses\OSmedia-base.php:239
actionwp_headclasses\OSmedia-base.php:241
actionadmin_enqueue_scriptsclasses\OSmedia-base.php:242
actioninitclasses\OSmedia-base.php:245
actioninitclasses\OSmedia-post-admin.php:630
actioninitclasses\OSmedia-post-admin.php:631
actioninitclasses\OSmedia-post-admin.php:632
actionadd_meta_boxesclasses\OSmedia-post-admin.php:633
actionsave_postclasses\OSmedia-post-admin.php:634
filteris_protected_metaclasses\OSmedia-post-admin.php:636
actioninitclasses\OSmedia-post-frontend.php:389
filtertemplate_includeclasses\OSmedia-post-frontend.php:397
actionadmin_menuclasses\OSmedia-settings.php:71
actioninitclasses\OSmedia-settings.php:76
actionadmin_initclasses\OSmedia-settings.php:77
filterfilter_old_varsclasses\OSmedia-settings.php:80
filterfilter_old_vars_adminclasses\OSmedia-version-vars.php:40
actioninitincludes\admin-notice-helper\admin-notice-helper.php:44
actionadmin_noticesincludes\admin-notice-helper\admin-notice-helper.php:45
actionshutdownincludes\admin-notice-helper\admin-notice-helper.php:46
Maintenance & Trust

OS media – HTML5 Featured Video Maintenance & Trust

Maintenance Signals

WordPress version tested4.6.30
Last updatedOct 16, 2016
PHP min version
Downloads10K

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

OS media – HTML5 Featured Video Developer Profile

mario marino

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect OS media – HTML5 Featured Video

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/os-media/player/videojs/video-js.css/wp-content/plugins/os-media/player/videojs/skin/video-js.css/wp-content/plugins/os-media/player/videojs/video.js/wp-content/plugins/os-media/player/videojs/videojs-youtube.js/wp-content/plugins/os-media/javascript/OSmedia.js/wp-content/plugins/os-media/css/admin.css
Script Paths
/wp-content/plugins/os-media/player/videojs/video.js/wp-content/plugins/os-media/player/videojs/videojs-youtube.js/wp-content/plugins/os-media/javascript/OSmedia.js
Version Parameters
os-media/javascript/OSmedia.js?ver=os-media/css/admin.css?ver=

HTML / DOM Fingerprints

CSS Classes
OSmedia_video
HTML Comments
PROVVISORIO !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
Data Attributes
data-osmedia-videostream-filedata-osmedia-videostream-file-typedata-osmedia-videostream-imagedata-osmedia-videostream-poster
JS Globals
OSmediaOSmedia_settings
Shortcode Output
[OSmedia_video
FAQ

Frequently Asked Questions about OS media – HTML5 Featured Video