
Post Video Metabox Security & Risk Analysis
wordpress.org/plugins/post-video-metaboxAdd Video URL Metabox to the post format video and show the video player in the single post thumbnail which can click to play on the thumbnail.
Is Post Video Metabox Safe to Use in 2026?
Generally Safe
Score 85/100Post Video Metabox has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "post-video-metabox" plugin version 2.0.0 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of identified AJAX handlers, REST API routes, shortcodes, cron events, and file operations significantly limits the potential attack surface. Furthermore, the plugin demonstrates good practices by utilizing prepared statements for all SQL queries and incorporating nonce and capability checks, which are crucial for preventing common web vulnerabilities. The lack of any reported CVEs, historical or current, is a very positive indicator of its security.
However, a notable concern arises from the output escaping. With only 40% of the total outputs properly escaped, there is a significant risk of Cross-Site Scripting (XSS) vulnerabilities. This means that user-supplied data, if not handled carefully, could be injected into the output and executed by a user's browser. While taint analysis did not reveal any specific unsanitized flows, the low percentage of proper output escaping suggests that potential XSS vulnerabilities might exist but were not fully captured by the static analysis or may be latent.
In conclusion, the "post-video-metabox" plugin has a solid foundation in terms of attack surface and core security practices like SQL sanitization and authentication checks. The primary weakness lies in the insufficient output escaping, which should be addressed to mitigate the risk of XSS attacks. Given the clean vulnerability history, it is likely that this is an oversight that can be corrected. The plugin is recommended for use, but with a caution regarding potential XSS if user input is displayed without adequate sanitization.
Key Concerns
- Insufficient output escaping
Post Video Metabox Security Vulnerabilities
Post Video Metabox Release Timeline
Post Video Metabox Code Analysis
Output Escaping
Post Video Metabox Attack Surface
WordPress Hooks 6
Maintenance & Trust
Post Video Metabox Maintenance & Trust
Maintenance Signals
Community Trust
Post Video Metabox Alternatives
Bulk Convert Post Format
bulk-convert-post-format
Bulk convert posts in a category to a selected post format.
WP Videos
video-sync-for-vimeo
WP Videos creates Video post types that you can easily add Vimeo, YouTube, WordPress, Shortcode or custom embed (third party) HTML and JS videos to.
Dadevarzan Video Post Type
dadevarzan-wp-video
Dadevarzan Video Post Type
IFTTT Post Formats & Post Types
ifttt-post-formats
Set a post format or post type for your IFTTT-created posts via a post format or post type category.
ytSubscribe – Youtube Subscribe Button
ytsubscribe
Automatically Add Youtube Subscribe Button Below each Video WordPress Plugin
Post Video Metabox Developer Profile
3 plugins · 20 total installs
How We Detect Post Video Metabox
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/post-video-metabox/css/admin/admin.min.css/wp-content/plugins/post-video-metabox/js/admin/admin.min.js/wp-content/plugins/post-video-metabox/css/frontend/plugin.min.css/wp-content/plugins/post-video-metabox/js/frontend/frontend.min.jspost-video-metabox/css/admin/admin.min.css?ver=post-video-metabox/js/admin/admin.min.js?ver=post-video-metabox/css/frontend/plugin.min.css?ver=post-video-metabox/js/frontend/frontend.min.js?ver=HTML / DOM Fingerprints
pvt-metaboxes-classicadd-post-video-textadd-post-video-buttonpvt-metaboxespvt-video-thumbnailpvt-video-thumbnail-overlayvideo-iconpvt-video-thumbnail-srcid="pvt_post_video_meta_box_classic"id="pvt_post_video_meta_box"window.wp