PingVid Security & Risk Analysis

wordpress.org/plugins/pingvid

Floating YouTube video that autoplays muted on load and expands with sound on click—perfect for Shorts and promos.

10 active installs v1.1.1 PHP 7.4+ WP 6.4+ Updated Unknown
embedfloatingpopupstickyvideo
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is PingVid Safe to Use in 2026?

Generally Safe

Score 100/100

PingVid has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

Based on the static analysis and vulnerability history provided, the pingvid plugin v1.1.1 exhibits a strong security posture. The absence of any identified dangerous functions, SQL injection vulnerabilities, file operations, external HTTP requests, or unsanitized taint flows is a significant strength. The plugin also demonstrates good practices by exclusively using prepared statements for SQL queries and properly escaping all output, indicating a robust defense against common web vulnerabilities. Furthermore, the clean vulnerability history with zero recorded CVEs suggests a commitment to security by the developers or a lack of historically significant security flaws.

However, a notable concern arises from the complete lack of nonce checks and capability checks. While the current static analysis reports zero unprotected entry points, this absence of checks leaves the plugin vulnerable to potential cross-site request forgery (CSRF) attacks if any new entry points are introduced or if existing ones are inadvertently exposed without proper authorization. The bundled Freemius library at v1.0, while not explicitly flagged as vulnerable in this report, represents a potential risk if it contains known or undiscovered vulnerabilities that are not patched within the plugin itself. The overall security is good due to the implemented safe coding practices, but the lack of authentication on potential entry points presents a latent risk that should be addressed.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
  • Bundled outdated library (Freemius v1.0)
Vulnerabilities
None known

PingVid Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

PingVid Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
149 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Freemius1.0

Output Escaping

100% escaped149 total outputs
Attack Surface

PingVid Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionadmin_enqueue_scriptsadmin\admin.php:23
actionadmin_menuadmin\admin.php:24
actiondevnet_pingvid_form_topadmin\settings.php:59
filteris_submenu_visiblepingvid.php:87
actionafter_uninstallpingvid.php:93
actionplugins_loadedpingvid.php:115
actionwp_enqueue_scriptspublic\public.php:18
actionwp_footerpublic\public.php:19
Maintenance & Trust

PingVid Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedUnknown
PHP min version7.4
Downloads446

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

PingVid Developer Profile

Devnet

7 plugins · 6K total installs

93
trust score
Avg Security Score
98/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect PingVid

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/pingvid/assets/build/admin.css/wp-content/plugins/pingvid/assets/build/admin.js/wp-content/plugins/pingvid/assets/build/public.css/wp-content/plugins/pingvid/assets/build/public.js
Script Paths
/wp-content/plugins/pingvid/assets/color-picker/wp-color-picker-alpha.min.js
Version Parameters
pingvid/style.css?ver=pingvid?ver=pingvid/admin.css?ver=pingvid/admin.js?ver=pingvid/public.css?ver=pingvid/public.js?ver=

HTML / DOM Fingerprints

CSS Classes
devnet-pingvid-video-wrapperpingvid-close-buttondevnet-pingvid-play-button
HTML Comments
TODO: do uninstall logic.Run Freemius actions and filters.
Data Attributes
data-pingvid-iddata-pingvid-urldata-pingvid-autoplaydata-pingvid-loopdata-pingvid-mute
JS Globals
devnet_pingvid_script_datadevnet_pingvid_fsdevnet_esub_is_submenu_visibledevnet_pingvid_fs_uninstall_cleanup
FAQ

Frequently Asked Questions about PingVid