Pipe Audio Video and Screen Recorder Security & Risk Analysis

wordpress.org/plugins/pipe-audio-video-and-screen-recorder

This plugin simplifies the integration between the Pipe Platform and WordPress. It lets your website users and visitors record audio, video, and scree …

10 active installs v1.0.7 PHP + WP 4.9+ Updated Sep 22, 2025
audio-recorderscreen-recordervideovideo-recorderwebcam
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Pipe Audio Video and Screen Recorder Safe to Use in 2026?

Generally Safe

Score 100/100

Pipe Audio Video and Screen Recorder has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6mo ago
Risk Assessment

The "pipe-audio-video-and-screen-recorder" plugin v1.0.7 exhibits a generally strong security posture based on static analysis. A high percentage of SQL queries utilize prepared statements, and all identified output operations are properly escaped, significantly mitigating risks of SQL injection and Cross-Site Scripting (XSS). The absence of known CVEs and a clean vulnerability history further bolster this positive assessment, suggesting good development practices and a lack of historically exploitable flaws.

However, a notable concern arises from the presence of one AJAX handler that lacks authentication checks. This represents a direct entry point that could be exploited by unauthenticated users. While the taint analysis did not reveal critical or high-severity unsanitized flows, the existence of flows with unsanitized paths, even if not critically scored, warrants attention. The plugin's attack surface is relatively small, but the unprotected AJAX handler is a clear weakness.

In conclusion, the plugin demonstrates strengths in secure coding practices regarding data handling and output. The lack of historical vulnerabilities is a significant positive. The primary weakness lies in the unprotected AJAX handler, which introduces a direct security risk that needs to be addressed to achieve a fully secure state. Addressing this single point of vulnerability would substantially improve the plugin's security profile.

Key Concerns

  • Unprotected AJAX handler
Vulnerabilities
None known

Pipe Audio Video and Screen Recorder Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Pipe Audio Video and Screen Recorder Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
17 prepared
Unescaped Output
0
163 escaped
Nonce Checks
6
Capability Checks
3
File Operations
3
External Requests
1
Bundled Libraries
0

SQL Query Safety

94% prepared18 total queries

Output Escaping

100% escaped163 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

5 flows2 with unsanitized paths
addpipe_ajax_save_settings (load\AddPipe.php:997)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Pipe Audio Video and Screen Recorder Attack Surface

Entry Points8
Unprotected1

AJAX Handlers 6

authwp_ajax_addpipe_ajax_save_settingsload\AddPipe.php:149
authwp_ajax_addpipe_ajax_shortcode_generatorload\AddPipe.php:151
authwp_ajax_addpipe_download_fileload\AddPipe.php:153
authwp_ajax_delete_recordingload\AddPipe.php:155
authwp_ajax_addpipe_ajax_sync_deletedload\AddPipe.php:157
noprivwp_ajax_addpipeWebhookload\AddPipe.php:160

Shortcodes 2

[pipe_recorder] load\AddPipe.php:162
[pipe_playback] load\AddPipe.php:166
WordPress Hooks 4
actionadmin_menuload\AddPipe.php:146
actionadmin_enqueue_scriptsload\AddPipe.php:171
actionwp_enqueue_scriptsload\AddPipe.php:173
actionadmin_enqueue_scriptsload\AddPipe.php:175
Maintenance & Trust

Pipe Audio Video and Screen Recorder Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 22, 2025
PHP min version
Downloads591

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Pipe Audio Video and Screen Recorder Developer Profile

addpipe

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Pipe Audio Video and Screen Recorder

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/pipe-audio-video-and-screen-recorder/css/admin/embedRecorder.css/wp-content/plugins/pipe-audio-video-and-screen-recorder/js/admin/embedRecorder.js/wp-content/plugins/pipe-audio-video-and-screen-recorder/css/admin/recordedRecordings.css/wp-content/plugins/pipe-audio-video-and-screen-recorder/js/admin/recordedRecordings.js
Version Parameters
pipe-audio-video-and-screen-recorder/css/admin/embedRecorder.css?ver=2.0pipe-audio-video-and-screen-recorder/js/admin/embedRecorder.js?ver=2.0pipe-audio-video-and-screen-recorder/css/admin/recordedRecordings.css?ver=2.0pipe-audio-video-and-screen-recorder/js/admin/recordedRecordings.js?ver=2.0

HTML / DOM Fingerprints

HTML Comments
<!-- No direct access --><!-- Error #845173685 -->
Data Attributes
data-addpipe-envdata-addpipe-account-hash
JS Globals
addpipeAdmin
Shortcode Output
<div class="addpipe-recorder"<div class="addpipe-playback"
FAQ

Frequently Asked Questions about Pipe Audio Video and Screen Recorder