
PlayerJS Security & Risk Analysis
wordpress.org/plugins/playerjsThe official plugin for PlayerJS.com - video & audio player builder. Make an awesome player for your website for free.
Is PlayerJS Safe to Use in 2026?
Use With Caution
Score 69/100PlayerJS has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
Player.js version 2.24 exhibits a generally good security posture based on the static analysis provided. The absence of dangerous functions, reliance on prepared statements for SQL queries, and proper output escaping are all positive indicators. The limited attack surface with no unprotected entry points is also commendable. However, the vulnerability history presents a significant concern. With two known CVEs, one of which remains unpatched, there is a clear and present risk to users of this version. The historical prevalence of Cross-Site Scripting vulnerabilities suggests a potential ongoing weakness in input sanitization or rendering, even if current static analysis did not detect specific flaws.
While the code itself appears to follow many secure coding practices, the unpatched vulnerability is a critical indicator of risk. This suggests that even if the current version passes static analysis, it is not free from known security flaws. The existence of past XSS vulnerabilities, coupled with an unpatched CVE, necessitates caution. The plugin's strengths lie in its clean code practices, but its weakness is the documented and unaddressed security flaw, making it a medium to high risk for environments where security is a priority.
Key Concerns
- Unpatched CVE
- Known historical XSS vulnerabilities
- No nonce checks
- No capability checks
PlayerJS Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
PlayerJS <= 2.24 - Authenticated (Contributor+) Stored Cross-Site Scripting
PlayerJS <= 2.23 - Authenticated (Contributor+) Stored Cross-Site Scripting
PlayerJS Code Analysis
Output Escaping
PlayerJS Attack Surface
Shortcodes 1
WordPress Hooks 10
Maintenance & Trust
PlayerJS Maintenance & Trust
Maintenance Signals
Community Trust
PlayerJS Alternatives
StreamNexus.io Embed Videos
streamnexus-io-embed-videos
Easily embed StreamNexus.io hosted videos using a shortcode. The plugin embeds an HTML5 ABR HLS video player.
AudioIgniter Music Player
audioigniter
AudioIgniter lets you create music playlists and embed them in your WordPress posts, pages or custom post types and serve your audio content in style!
CP Media Player – Audio Player and Video Player
audio-and-video-player
CP Media Player - Audio and Video Player supported by major browsers, such as IE, Firefox, Opera, Safari, Chrome, and mobile devices: iPhone, iPad, An …
Lean Player – Video and Audio Player for WordPress, Elementor, Block Editor and Classic Editor
az-video-and-audio-player-addon-for-elementor
WordPress Video Player & Audio Player plugin - simple, lightweight and customizable HTML5, YouTube, Vimeo & mp3 media player that supports all devices
FV Player 8
fv-player
WordPress's most reliable, easy to use and feature-rich video player. Supports playlists, ads, stats and user video position saving.
PlayerJS Developer Profile
1 plugin · 1K total installs
How We Detect PlayerJS
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/playerjs/playerjs_default.js/wp-content/plugins/playerjs/playerjs_default.jsHTML / DOM Fingerprints
data-playerjs-idPlayerjsAsyncPlayerjs<div id="playerjs<center><div id="playerjs