
WP Video Popup – WordPress Video Lightbox for YouTube, Rumble & Vimeo Security & Risk Analysis
wordpress.org/plugins/responsive-youtube-vimeo-popupWP Video Popup lets you add a responsive YouTube, Rumble or Vimeo video lightbox to any page, post or custom post type of your website.
Is WP Video Popup – WordPress Video Lightbox for YouTube, Rumble & Vimeo Safe to Use in 2026?
Generally Safe
Score 100/100WP Video Popup – WordPress Video Lightbox for YouTube, Rumble & Vimeo has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "responsive-youtube-vimeo-popup" plugin version 2.10.4 demonstrates a generally strong security posture based on the provided static analysis. It employs proper input validation and output sanitization, with 100% of outputs being properly escaped and all SQL queries utilizing prepared statements. The presence of nonce and capability checks on its entry points, including AJAX handlers and shortcodes, further mitigates common attack vectors. There are no identified dangerous functions, file operations, or critical/high severity taint flows, indicating a well-written codebase in these areas.
However, the analysis does note a single external HTTP request, which, while not inherently a vulnerability, represents a potential attack surface if not handled securely. The absence of any recorded historical vulnerabilities is a positive sign, suggesting a consistent track record of secure development. Despite this, the lack of taint analysis data (0 flows analyzed) makes it impossible to definitively rule out all potential injection vulnerabilities that might not be caught by static checks alone.
In conclusion, the plugin appears to be developed with security in mind, utilizing best practices for WordPress plugin development. The identified external HTTP request is a minor point of attention, but the overall lack of detected vulnerabilities and adherence to security standards is commendable. Further dynamic analysis or a more comprehensive static analysis covering taint flows would provide an even greater level of assurance.
Key Concerns
- External HTTP request present
WP Video Popup – WordPress Video Lightbox for YouTube, Rumble & Vimeo Security Vulnerabilities
WP Video Popup – WordPress Video Lightbox for YouTube, Rumble & Vimeo Code Analysis
Output Escaping
WP Video Popup – WordPress Video Lightbox for YouTube, Rumble & Vimeo Attack Surface
AJAX Handlers 2
Shortcodes 2
WordPress Hooks 13
Maintenance & Trust
WP Video Popup – WordPress Video Lightbox for YouTube, Rumble & Vimeo Maintenance & Trust
Maintenance Signals
Community Trust
WP Video Popup – WordPress Video Lightbox for YouTube, Rumble & Vimeo Alternatives
Video Popup for Elementor – WPTD
wptd-video-popup
Simple video popup plugin for elementor. You can make video lightbox popup in elementor. YouTube, Vimeo videos are supported.
Video PopUp
video-popup
The ultimate Video Popup plugin for WordPress. Create unlimited and responsive popups for YouTube, Vimeo, MP4 & WebM videos on click or On-Page Load.
Video Reviews / Video Widget
video-reviews
Transform your website with engaging video content. Add a powerful Video Reviews widget to your footer and boost conversions instantly.
Post Featured Video
post-featured-video
Post Featured Video is a very nifty responsive video plugin that helps your users to see a YouTube or Vimeo video or Custom HTML MP4 video
Video Lightbox For Guten Blocks
video-lightbox-for-guten-blocks
Elevate WordPress with "Video Lightbox for Guten Blocks". Streamline video embedding effortlessly for engaging content.
WP Video Popup – WordPress Video Lightbox for YouTube, Rumble & Vimeo Developer Profile
10 plugins · 121K total installs
How We Detect WP Video Popup – WordPress Video Lightbox for YouTube, Rumble & Vimeo
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/responsive-youtube-vimeo-popup/assets/img/wp-video-popup-logo-1.png/wp-content/plugins/responsive-youtube-vimeo-popup/assets/js/review-notice.js/wp-content/plugins/responsive-youtube-vimeo-popup/assets/css/activation-notice.css/wp-content/plugins/responsive-youtube-vimeo-popup/assets/css/heatbox.css/wp-content/plugins/responsive-youtube-vimeo-popup/assets/css/admin-page.css/wp-content/plugins/responsive-youtube-vimeo-popup/assets/js/admin-page.js/wp-content/plugins/responsive-youtube-vimeo-popup/assets/css/wp-video-popup.css/wp-content/plugins/responsive-youtube-vimeo-popup/assets/js/review-notice.js/wp-content/plugins/responsive-youtube-vimeo-popup/assets/js/admin-page.jsresponsive-youtube-vimeo-popup/assets/js/review-notice.js?ver=responsive-youtube-vimeo-popup/assets/css/activation-notice.css?ver=responsive-youtube-vimeo-popup/assets/css/heatbox.css?ver=responsive-youtube-vimeo-popup/assets/css/admin-page.css?ver=responsive-youtube-vimeo-popup/assets/js/admin-page.js?ver=responsive-youtube-vimeo-popup/assets/css/wp-video-popup.css?ver=HTML / DOM Fingerprints
wpvp-activation-noticewp-video-popup-review-noticeheatbox-adminhas-headerdata-dismissible="wp-video-popup-pro-ad-forever"WPVideoPopupDismissal