
Spreebie Transcoder – Resize, Compress and Store Video Security & Risk Analysis
wordpress.org/plugins/spreebie-transcoderSPREEBIE TRANSCODER is a WordPress plugin that resizes, compresses and stores MP4 video via FFmpeg and Google Cloud Storage.
Is Spreebie Transcoder – Resize, Compress and Store Video Safe to Use in 2026?
Generally Safe
Score 85/100Spreebie Transcoder – Resize, Compress and Store Video has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The spreebie-transcoder plugin, version 1.0.1, exhibits a mixed security posture. On the positive side, it has a small attack surface with all entry points being protected by authorization checks. Furthermore, all SQL queries utilize prepared statements, and there are no known vulnerabilities (CVEs) associated with this plugin. The presence of nonce checks and capability checks suggests an awareness of WordPress security best practices.
However, several concerns warrant attention. The plugin utilizes dangerous functions such as `exec` and `shell_exec`, which can pose significant risks if not handled with extreme care, especially when dealing with user-supplied input. The taint analysis reveals a flow with unsanitized paths, which, while not classified as critical or high severity in this report, is a strong indicator of potential command injection vulnerabilities. Additionally, the output escaping is only 56% proper, meaning a substantial portion of the plugin's output could be vulnerable to cross-site scripting (XSS) attacks.
The absence of any recorded vulnerabilities in its history is a positive sign, suggesting the developers may have a good track record or have not been targeted. However, this should not overshadow the immediate risks identified in the static analysis. The combination of dangerous function usage, unsanitized paths, and poor output escaping creates a notable risk profile despite the lack of known CVEs and protected entry points. Further investigation into how the `exec` and `shell_exec` functions are used, and rigorous sanitization of any data influencing file paths, is strongly recommended.
Key Concerns
- Use of dangerous functions (exec, shell_exec)
- Flow with unsanitized paths
- Low percentage of properly escaped output
- Bundled outdated library (Guzzle)
Spreebie Transcoder – Resize, Compress and Store Video Security Vulnerabilities
Spreebie Transcoder – Resize, Compress and Store Video Code Analysis
Dangerous Functions Found
Bundled Libraries
Output Escaping
Data Flow Analysis
Spreebie Transcoder – Resize, Compress and Store Video Attack Surface
AJAX Handlers 2
WordPress Hooks 8
Maintenance & Trust
Spreebie Transcoder – Resize, Compress and Store Video Maintenance & Trust
Maintenance Signals
Community Trust
Spreebie Transcoder – Resize, Compress and Store Video Alternatives
Open Beacon MP4 Conversion and Compression
open-beacon-mp4-conversion-and-compression
Easily convert video to MP4 and compress existing MP4 files to smaller sizes for WordPress media or to save locally for a variety of other uses.
SpeedSize Image & Video AI-Optimizer
speedsize-ai-image-optimizer
SpeedSize Image & Video AI-Optimizer plugin allows you to easily use SpeedSize's Neuroscience Media Optimization on your WP website.
Video Share VOD – Turnkey Video Site Builder Script
video-share-vod
Build your own VOD platform with Video Share VOD, featuring extensive video management, monetization, and HTML5 support.
Reimage Optimizer
reimage-optimizer
Short Description: Optimize and compress images and videos in WordPress. Improve speed and SEO with HLS, logs, and troubleshooting tools.
Flux Media Optimizer by Flux Plugins
flux-media-optimizer
Automatically optimize images, compress videos, and deliver media via global CDN. Boost Core Web Vitals and SEO with 50-70% smaller file sizes.
Spreebie Transcoder – Resize, Compress and Store Video Developer Profile
3 plugins · 120 total installs
How We Detect Spreebie Transcoder – Resize, Compress and Store Video
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/spreebie-transcoder/includes/spreebie-transcoder-upload.css/wp-content/plugins/spreebie-transcoder/includes/spreebie-transcoder-upload.js/wp-content/plugins/spreebie-transcoder/includes/spreebie-transcoder-upload.jsspreebie-transcoder/includes/spreebie-transcoder-upload.css?ver=spreebie-transcoder/includes/spreebie-transcoder-upload.js?ver=HTML / DOM Fingerprints
spreebie_transcoder_upload_occuredspreebie_transcoder_gcs_ajax_data