Responsive Media Security & Risk Analysis

wordpress.org/plugins/responsive-media

Wordpress plugin for responsive embedded media (oEmbed) like Youtube, Vimeo, Flickr, Kickstarter, Slideshare, Soundcloud, Speakerdeck, TED & Vine.

40 active installs v1.2.0 PHP + WP 4.0.0+ Updated May 29, 2018
mediaresponsivevideovimeoyoutube
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Responsive Media Safe to Use in 2026?

Generally Safe

Score 85/100

Responsive Media has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The "responsive-media" plugin version 1.2.0 demonstrates a strong adherence to fundamental security practices regarding its attack surface. The absence of AJAX handlers, REST API routes, shortcodes, and cron events with unprotected entry points significantly reduces the plugin's exposure to external manipulation. Furthermore, the code's use of prepared statements for its single SQL query is commendable. However, the analysis reveals a critical weakness in output escaping, with 100% of outputs not being properly escaped. This represents a substantial risk for Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the content displayed by the plugin. The lack of any recorded vulnerability history is a positive sign, suggesting the plugin has been relatively secure in the past. Nonetheless, the identified output escaping flaw is a serious concern that warrants immediate attention. The plugin's strengths lie in its limited attack surface and secure database interaction, but the complete lack of output sanitization presents a significant security gap.

Key Concerns

  • 100% of outputs not properly escaped
Vulnerabilities
None known

Responsive Media Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Responsive Media Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

0% escaped1 total outputs
Attack Surface

Responsive Media Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_menuresponsive-media.php:47
actionadmin_initresponsive-media.php:48
filterwp_headresponsive-media.php:53
filterembed_oembed_htmlresponsive-media.php:54
Maintenance & Trust

Responsive Media Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedMay 29, 2018
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs40
Developer Profile

Responsive Media Developer Profile

jeroenooms

1 plugin · 40 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Responsive Media

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/responsive-media/responsive-media.php

HTML / DOM Fingerprints

CSS Classes
responsive-media
Data Attributes
data-responsive-media
FAQ

Frequently Asked Questions about Responsive Media