WP Video Popup – WordPress Video Lightbox for YouTube, Rumble & Vimeo Security & Risk Analysis

wordpress.org/plugins/responsive-youtube-vimeo-popup

WP Video Popup lets you add a responsive YouTube, Rumble or Vimeo video lightbox to any page, post or custom post type of your website.

9K active installs v2.10.4 PHP + WP 4.0+ Updated Feb 23, 2026
rumble-lightboxvideo-lightboxvideo-popupvimeo-lightboxyoutube-lightbox
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP Video Popup – WordPress Video Lightbox for YouTube, Rumble & Vimeo Safe to Use in 2026?

Generally Safe

Score 100/100

WP Video Popup – WordPress Video Lightbox for YouTube, Rumble & Vimeo has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "responsive-youtube-vimeo-popup" plugin version 2.10.4 demonstrates a generally strong security posture based on the provided static analysis. It employs proper input validation and output sanitization, with 100% of outputs being properly escaped and all SQL queries utilizing prepared statements. The presence of nonce and capability checks on its entry points, including AJAX handlers and shortcodes, further mitigates common attack vectors. There are no identified dangerous functions, file operations, or critical/high severity taint flows, indicating a well-written codebase in these areas.

However, the analysis does note a single external HTTP request, which, while not inherently a vulnerability, represents a potential attack surface if not handled securely. The absence of any recorded historical vulnerabilities is a positive sign, suggesting a consistent track record of secure development. Despite this, the lack of taint analysis data (0 flows analyzed) makes it impossible to definitively rule out all potential injection vulnerabilities that might not be caught by static checks alone.

In conclusion, the plugin appears to be developed with security in mind, utilizing best practices for WordPress plugin development. The identified external HTTP request is a minor point of attention, but the overall lack of detected vulnerabilities and adherence to security standards is commendable. Further dynamic analysis or a more comprehensive static analysis covering taint flows would provide an even greater level of assurance.

Key Concerns

  • External HTTP request present
Vulnerabilities
None known

WP Video Popup – WordPress Video Lightbox for YouTube, Rumble & Vimeo Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WP Video Popup – WordPress Video Lightbox for YouTube, Rumble & Vimeo Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
30 escaped
Nonce Checks
2
Capability Checks
3
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

100% escaped30 total outputs
Attack Surface

WP Video Popup – WordPress Video Lightbox for YouTube, Rumble & Vimeo Attack Surface

Entry Points4
Unprotected0

AJAX Handlers 2

authwp_ajax_dismiss_admin_noticeinc\persist-admin-notices-dismissal\persist-admin-notices-dismissal.php:47
authwp_ajax_wp_video_popup_review_notice_dismissalresponsive-youtube-vimeo-popup.php:165

Shortcodes 2

[wp-video-popup] responsive-youtube-vimeo-popup.php:344
[ryv-popup] responsive-youtube-vimeo-popup.php:345
WordPress Hooks 13
actionadmin_menuinc\init.php:16
filterplugin_action_linksinc\init.php:45
actionadmin_enqueue_scriptsinc\persist-admin-notices-dismissal\persist-admin-notices-dismissal.php:46
filterpand_dismiss_notice_js_urlinc\persist-admin-notices-dismissal\persist-admin-notices-dismissal.php:57
actionadmin_initinc\settings.php:48
actionadmin_noticesresponsive-youtube-vimeo-popup.php:68
actionadmin_initresponsive-youtube-vimeo-popup.php:69
actioninitresponsive-youtube-vimeo-popup.php:84
actionadmin_noticesresponsive-youtube-vimeo-popup.php:143
actionadmin_enqueue_scriptsresponsive-youtube-vimeo-popup.php:195
actionadmin_enqueue_scriptsresponsive-youtube-vimeo-popup.php:217
filteradmin_body_classresponsive-youtube-vimeo-popup.php:237
actionwp_enqueue_scriptsresponsive-youtube-vimeo-popup.php:248
Maintenance & Trust

WP Video Popup – WordPress Video Lightbox for YouTube, Rumble & Vimeo Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 23, 2026
PHP min version
Downloads332K

Community Trust

Rating82/100
Number of ratings43
Active installs9K
Developer Profile

WP Video Popup – WordPress Video Lightbox for YouTube, Rumble & Vimeo Developer Profile

David Vongries

10 plugins · 121K total installs

76
trust score
Avg Security Score
95/100
Avg Patch Time
607 days
View full developer profile
Detection Fingerprints

How We Detect WP Video Popup – WordPress Video Lightbox for YouTube, Rumble & Vimeo

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/responsive-youtube-vimeo-popup/assets/img/wp-video-popup-logo-1.png/wp-content/plugins/responsive-youtube-vimeo-popup/assets/js/review-notice.js/wp-content/plugins/responsive-youtube-vimeo-popup/assets/css/activation-notice.css/wp-content/plugins/responsive-youtube-vimeo-popup/assets/css/heatbox.css/wp-content/plugins/responsive-youtube-vimeo-popup/assets/css/admin-page.css/wp-content/plugins/responsive-youtube-vimeo-popup/assets/js/admin-page.js/wp-content/plugins/responsive-youtube-vimeo-popup/assets/css/wp-video-popup.css
Script Paths
/wp-content/plugins/responsive-youtube-vimeo-popup/assets/js/review-notice.js/wp-content/plugins/responsive-youtube-vimeo-popup/assets/js/admin-page.js
Version Parameters
responsive-youtube-vimeo-popup/assets/js/review-notice.js?ver=responsive-youtube-vimeo-popup/assets/css/activation-notice.css?ver=responsive-youtube-vimeo-popup/assets/css/heatbox.css?ver=responsive-youtube-vimeo-popup/assets/css/admin-page.css?ver=responsive-youtube-vimeo-popup/assets/js/admin-page.js?ver=responsive-youtube-vimeo-popup/assets/css/wp-video-popup.css?ver=

HTML / DOM Fingerprints

CSS Classes
wpvp-activation-noticewp-video-popup-review-noticeheatbox-adminhas-header
Data Attributes
data-dismissible="wp-video-popup-pro-ad-forever"
JS Globals
WPVideoPopupDismissal
FAQ

Frequently Asked Questions about WP Video Popup – WordPress Video Lightbox for YouTube, Rumble & Vimeo