
Post Featured Video Security & Risk Analysis
wordpress.org/plugins/post-featured-videoPost Featured Video is a very nifty responsive video plugin that helps your users to see a YouTube or Vimeo video or Custom HTML MP4 video
Is Post Featured Video Safe to Use in 2026?
Mostly Safe
Score 78/100Post Featured Video is generally safe to use. 1 past CVE were resolved. Keep it updated.
The 'post-featured-video' plugin v1.7 exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and performing a high percentage of output escaping. The absence of a large attack surface (AJAX, REST API, shortcodes, cron events) with direct user interaction points is also a strength. Furthermore, the presence of nonce and capability checks indicates an awareness of common WordPress security measures.
However, significant concerns arise from the 'unserialize' function, a known vector for deserialization vulnerabilities, especially if user-controlled input is passed to it without proper validation. While taint analysis shows no unsanitized flows in this specific scan, the mere presence of this dangerous function warrants caution. The plugin also makes an external HTTP request, which could be a potential point of exploitation if the target service is compromised or the request itself is mishandled. The vulnerability history, though marked as a medium severity CSRF in the past, is concerning as there is currently one unpatched CVE. This indicates a past security weakness and a potential ongoing risk if the vulnerability remains unresolved.
In conclusion, while the plugin has several secure coding practices in place, the use of 'unserialize', an external HTTP request, and the presence of an unpatched CVE present notable risks. The absence of critical or high-severity issues in the current taint analysis is a positive sign, but the plugin's history and the presence of 'unserialize' necessitate careful monitoring and prompt patching of any identified vulnerabilities.
Key Concerns
- Unpatched CVE exists
- Dangerous function: unserialize used
- External HTTP request made
Post Featured Video Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Post Featured Video <= 1.7 - Cross-Site Request Forgery
Post Featured Video Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
Post Featured Video Attack Surface
WordPress Hooks 11
Maintenance & Trust
Post Featured Video Maintenance & Trust
Maintenance Signals
Community Trust
Post Featured Video Alternatives
Video PopUp
video-popup
The ultimate Video Popup plugin for WordPress. Create unlimited and responsive popups for YouTube, Vimeo, MP4 & WebM videos on click or On-Page Load.
WP Video Popup – WordPress Video Lightbox for YouTube, Rumble & Vimeo
responsive-youtube-vimeo-popup
WP Video Popup lets you add a responsive YouTube, Rumble or Vimeo video lightbox to any page, post or custom post type of your website.
Video Popup for Elementor – WPTD
wptd-video-popup
Simple video popup plugin for elementor. You can make video lightbox popup in elementor. YouTube, Vimeo videos are supported.
Video Reviews / Video Widget
video-reviews
Transform your website with engaging video content. Add a powerful Video Reviews widget to your footer and boost conversions instantly.
Video Lightbox For Guten Blocks
video-lightbox-for-guten-blocks
Elevate WordPress with "Video Lightbox for Guten Blocks". Streamline video embedding effortlessly for engaging content.
Post Featured Video Developer Profile
40 plugins · 25K total installs
How We Detect Post Featured Video
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/post-featured-video/assets/css/backend-style.css/wp-content/plugins/post-featured-video/assets/css/frontend-style.css/wp-content/plugins/post-featured-video/assets/js/lightbox.min.js/wp-content/plugins/post-featured-video/assets/js/video-uploader.jspfv_lightbox_scrptpfv_frontnd_stylepfv_vid_uploaderpfv_backend_styleHTML / DOM Fingerprints
pfv_bttn_sectpfvvideourlpfv_uploader_video_buttonpfv_remove_fetured_videodata-pfv-video-iddata-pfv-typedata-pfv-video-url