Smartideo Security & Risk Analysis

wordpress.org/plugins/smartideo

Smartideo 是为 WordPress 添加对在线视频支持的一款插件(支持手机、平板等设备HTML5播放)。

1K active installs v2.8.1 PHP + WP 3.5.0+ Updated May 10, 2025
bilibiliplayertencentvideoyoutube
100
A · Safe
CVEs total1
Unpatched0
Last CVEJul 26, 2022
Safety Verdict

Is Smartideo Safe to Use in 2026?

Generally Safe

Score 100/100

Smartideo has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Jul 26, 2022Updated 10mo ago
Risk Assessment

The smartideo plugin v2.8.1 demonstrates a generally strong security posture based on the provided static analysis. It boasts a zero attack surface for common entry points like AJAX, REST API, shortcodes, and cron events, with no identified unprotected endpoints. The code also adheres to good practices by avoiding dangerous functions, performing all SQL queries with prepared statements, and having no file operations or external HTTP requests. Furthermore, the presence of nonce and capability checks indicates an effort to implement basic authorization and security measures. However, there is a minor concern regarding output escaping, with 17% of outputs not being properly escaped, which could potentially lead to cross-site scripting vulnerabilities if untrusted data is handled in those specific instances.

The vulnerability history of smartideo reveals a single medium-severity CVE in the past, related to cross-site scripting. While there are no currently unpatched vulnerabilities and the last recorded vulnerability was over a year ago, this past incident serves as a reminder that XSS is a potential risk. The lack of critical or high-severity vulnerabilities and the absence of critical or high taint flows in the static analysis are positive signs, suggesting that the plugin has been actively maintained and improved. Overall, smartideo appears to be a reasonably secure plugin, with its main area for improvement being the complete sanitization of all output to eliminate any residual XSS risks.

Key Concerns

  • Unescaped output detected
Vulnerabilities
1

Smartideo Security Vulnerabilities

CVEs by Year

1 CVE in 2022
2022
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

WF-6be64d8d-fc71-40c2-baa8-985445d953ea-smartideomedium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

SmartIdeo <= 2.7.0 - Stored Cross-Site Scripting

Jul 26, 2022 Patched in 2.7.1 (546d)
Code Analysis
Analyzed Mar 16, 2026

Smartideo Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
5 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

83% escaped6 total outputs
Attack Surface

Smartideo Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionadmin_menusmartideo.php:26
actionwp_enqueue_scriptssmartideo.php:38
Maintenance & Trust

Smartideo Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMay 10, 2025
PHP min version
Downloads99K

Community Trust

Rating100/100
Number of ratings6
Active installs1K
Developer Profile

Smartideo Developer Profile

Fens Liu

1 plugin · 1K total installs

79
trust score
Avg Security Score
100/100
Avg Patch Time
546 days
View full developer profile
Detection Fingerprints

How We Detect Smartideo

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/smartideo/smartideo.js/wp-content/plugins/smartideo/smartideo.css
Script Paths
/wp-content/plugins/smartideo/smartideo.js
Version Parameters
smartideo/smartideo.js?ver=smartideo/smartideo.css?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Smartideo