Post Media Manager: Image & Video Security & Risk Analysis

wordpress.org/plugins/post-media-manager-image-video

Add a featured video to any custom post. Includes a layout designer and shortcode display options.

0 active installs v1.0.0 PHP 7.4+ WP 6.0+ Updated May 14, 2025
featured-videolayout-designerpost-videovideo-displayvideo-layout
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Post Media Manager: Image & Video Safe to Use in 2026?

Generally Safe

Score 100/100

Post Media Manager: Image & Video has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10mo ago
Risk Assessment

The plugin "post-media-manager-image-video" v1.0.0 exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of dangerous functions, unsanitized taint flows, raw SQL queries, and file operations is highly commendable. All SQL queries utilize prepared statements, and output escaping is consistently applied, mitigating common risks like SQL injection and cross-site scripting.

However, the presence of two shortcodes as entry points, despite the analysis indicating none are unprotected, warrants careful consideration. While the code signals show a nonce check and a capability check are present, the specific implementation and coverage of these checks on the shortcode hooks are not detailed. A lack of comprehensive authentication and authorization checks on all entry points, even if currently reporting as zero unprotected, could become a concern if the plugin evolves.

The plugin's vulnerability history is exceptionally clean, with no recorded CVEs. This suggests a well-maintained codebase and a proactive approach to security by the developers. Overall, the plugin appears to be secure, with its primary strength lying in its clean codebase and robust handling of core security practices. The main area for vigilance would be ensuring the shortcode implementations are strictly secured against any potential future vulnerabilities.

Key Concerns

  • Shortcodes as entry points
Vulnerabilities
None known

Post Media Manager: Image & Video Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Post Media Manager: Image & Video Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
32 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped32 total outputs
Data Flows
All sanitized

Data Flow Analysis

1 flows
<post-media-manager-image-video> (post-media-manager-image-video.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Post Media Manager: Image & Video Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[postmema_post_layout] post-media-manager-image-video.php:184
[post_layout_display] post-media-manager-image-video.php:295
WordPress Hooks 14
actionadmin_menulayout-designer-page.php:2
actioninitpost-media-manager-image-video.php:36
actionadmin_enqueue_scriptspost-media-manager-image-video.php:46
actionadd_meta_boxespost-media-manager-image-video.php:55
actionsave_postpost-media-manager-image-video.php:113
actionwp_dashboard_setuppost-media-manager-image-video.php:122
actionadmin_initpost-media-manager-image-video.php:140
actionwp_enqueue_scriptspost-media-manager-image-video.php:190
actionadmin_initpost-media-manager-image-video.php:270
actioninitpost-media-manager-image-video.php:297
actionadmin_enqueue_scriptspost-media-manager-image-video.php:309
actionwp_enqueue_scriptspost-media-manager-image-video.php:314
actionwp_enqueue_scriptspost-media-manager-image-video.php:324
actionadmin_enqueue_scriptspost-media-manager-image-video.php:329
Maintenance & Trust

Post Media Manager: Image & Video Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedMay 14, 2025
PHP min version7.4
Downloads319

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Post Media Manager: Image & Video Developer Profile

primisdigital

3 plugins · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Post Media Manager: Image & Video

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/post-media-manager-image-video/css/postmema-admin.css/wp-content/plugins/post-media-manager-image-video/js/postmema-admin.js/wp-content/plugins/post-media-manager-image-video/css/postmema-frontend.css
Script Paths
/wp-content/plugins/post-media-manager-image-video/js/postmema-admin.js

HTML / DOM Fingerprints

CSS Classes
postmema-post-layoutpostmema-post-itempostmema-videopostmema-titlepostmema-excerptpostmema-readmorepostmema-upload-btnpostmema-remove-btn
Data Attributes
id="postmema-preview"id="postmema_video_id"name="postmema_video_id"id="postmema_video_meta_box"name="postmema_video_nonce"
JS Globals
postmema_options
Shortcode Output
<div class="postmema-post-layout"><div class="postmema-post-item"><div class="postmema-video"><video controls src
FAQ

Frequently Asked Questions about Post Media Manager: Image & Video