
PingVid Security & Risk Analysis
wordpress.org/plugins/pingvidFloating YouTube video that autoplays muted on load and expands with sound on click—perfect for Shorts and promos.
Is PingVid Safe to Use in 2026?
Generally Safe
Score 100/100PingVid has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the static analysis and vulnerability history provided, the pingvid plugin v1.1.1 exhibits a strong security posture. The absence of any identified dangerous functions, SQL injection vulnerabilities, file operations, external HTTP requests, or unsanitized taint flows is a significant strength. The plugin also demonstrates good practices by exclusively using prepared statements for SQL queries and properly escaping all output, indicating a robust defense against common web vulnerabilities. Furthermore, the clean vulnerability history with zero recorded CVEs suggests a commitment to security by the developers or a lack of historically significant security flaws.
However, a notable concern arises from the complete lack of nonce checks and capability checks. While the current static analysis reports zero unprotected entry points, this absence of checks leaves the plugin vulnerable to potential cross-site request forgery (CSRF) attacks if any new entry points are introduced or if existing ones are inadvertently exposed without proper authorization. The bundled Freemius library at v1.0, while not explicitly flagged as vulnerable in this report, represents a potential risk if it contains known or undiscovered vulnerabilities that are not patched within the plugin itself. The overall security is good due to the implemented safe coding practices, but the lack of authentication on potential entry points presents a latent risk that should be addressed.
Key Concerns
- Missing nonce checks
- Missing capability checks
- Bundled outdated library (Freemius v1.0)
PingVid Security Vulnerabilities
PingVid Code Analysis
Bundled Libraries
Output Escaping
PingVid Attack Surface
WordPress Hooks 8
Maintenance & Trust
PingVid Maintenance & Trust
Maintenance Signals
Community Trust
PingVid Alternatives
Greet Bubble — Video Welcome
greet-bubble
Create engaging video welcome bubbles to greet visitors, boost interaction, and make your WordPress site more memorable.
Lazy load videos and sticky control
lazy-load-videos-and-sticky-control
Lazy load and sticky your video. Super-easy and fun!
Floating Product Category for WooCommerce
floating-product-category-for-woocommerce
Floating Product Category for WooCommerce is a plugin to display WooCommerce Categories. With floating category sidebar users can access WooCommerce p …
My Sticky Bar – Floating Notification Bar & Sticky Header (formerly myStickymenu)
mystickymenu
Create a welcome notification bar for your website. Also, My Sticky Bar plugin can make your menu or header sticky to the top when scrolled 📌
Sticky Menu & Sticky Header
sticky-menu-or-anything-on-scroll
Sticky Menu or Sticky Header sticks elements at the top of the screen when you scroll, or create a floating sticky menu or fixed widget.
PingVid Developer Profile
7 plugins · 6K total installs
How We Detect PingVid
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/pingvid/assets/build/admin.css/wp-content/plugins/pingvid/assets/build/admin.js/wp-content/plugins/pingvid/assets/build/public.css/wp-content/plugins/pingvid/assets/build/public.js/wp-content/plugins/pingvid/assets/color-picker/wp-color-picker-alpha.min.jspingvid/style.css?ver=pingvid?ver=pingvid/admin.css?ver=pingvid/admin.js?ver=pingvid/public.css?ver=pingvid/public.js?ver=HTML / DOM Fingerprints
devnet-pingvid-video-wrapperpingvid-close-buttondevnet-pingvid-play-buttonTODO: do uninstall logic.Run Freemius actions and filters.data-pingvid-iddata-pingvid-urldata-pingvid-autoplaydata-pingvid-loopdata-pingvid-mutedevnet_pingvid_script_datadevnet_pingvid_fsdevnet_esub_is_submenu_visibledevnet_pingvid_fs_uninstall_cleanup