
Related Videos for JW Player Security & Risk Analysis
wordpress.org/plugins/related-videos-for-jw-playerIt creates the feed required from "Related Videos" add-on for JW Player, one for each Wordpress category.
Is Related Videos for JW Player Safe to Use in 2026?
Generally Safe
Score 99/100Related Videos for JW Player has a strong security track record. Known vulnerabilities have been patched promptly.
The 'related-videos-for-jw-player' plugin, version 1.2.1, exhibits a mixed security posture. On one hand, the static analysis reveals a very small attack surface with no apparent entry points that lack authentication. Furthermore, all SQL queries observed utilize prepared statements, which is a strong security practice. File operations and external HTTP requests are also absent, reducing potential attack vectors.
However, concerns arise from the output escaping and taint analysis. A significant portion (59%) of outputs are not properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. The presence of two unsanitized paths in the taint analysis, although not classified as critical or high severity in this scan, suggests potential for input manipulation that could lead to unintended behavior or vulnerabilities if not handled carefully. The plugin's vulnerability history also points to a past XSS vulnerability, reinforcing the concern around unescaped output.
While the plugin demonstrates good practices in areas like SQL and attack surface management, the lack of comprehensive output escaping and the presence of unsanitized taint flows are significant weaknesses that require attention. The absence of nonce and capability checks, combined with the unescaped outputs, creates a notable risk of XSS attacks, especially given the plugin's past vulnerability of this type.
Key Concerns
- Unescaped output detected
- Unsanitized paths in taint flows
- Past XSS vulnerability noted
- No nonce checks
- No capability checks
Related Videos for JW Player Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Related Videos for JW Player <= 1.2.0 - Reflected Cross-Site Scripting
Related Videos for JW Player Code Analysis
Output Escaping
Data Flow Analysis
Related Videos for JW Player Attack Surface
WordPress Hooks 5
Maintenance & Trust
Related Videos for JW Player Maintenance & Trust
Maintenance Signals
Community Trust
Related Videos for JW Player Alternatives
JW Player for WordPress
jw-player-7-for-wp
JW Player for WordPress enables you to publish videos on your WordPress posts and pages using the most popular video player on the web.
WP YouTube Player
wp-youtube-player
Insert Youtube Videos on WordPress blog.
WP Videos
video-sync-for-vimeo
WP Videos creates Video post types that you can easily add Vimeo, YouTube, WordPress, Shortcode or custom embed (third party) HTML and JS videos to.
WP-Parsi JW Player
wp-parsi-jwplayer
Create player with JW Player shortcode on-the-fly!
skiv video embedding
muse-ai
This plugin enables skiv.com oEmbed links, and adds shortcodes to easily embed videos hosted on skiv.com.
Related Videos for JW Player Developer Profile
13 plugins · 2K total installs
How We Detect Related Videos for JW Player
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/related-videos-for-jw-player/css/rvjwp-style.css/wp-content/plugins/related-videos-for-jw-player/js/rvjwp-script.js/wp-content/plugins/related-videos-for-jw-player/js/rvjwp-script.jsrelated-videos-for-jw-player/css/rvjwp-style.css?ver=related-videos-for-jw-player/js/rvjwp-script.js?ver=HTML / DOM Fingerprints
rvjwp-codeid="rvjwp-options"name="rvjwp-options"id="thumbnail"name="thumbnail"id="field"name="field"+6 moremyAjax<span class="code">'related': {'file': '?feed=related-feed