
Stream Video Player Security & Risk Analysis
wordpress.org/plugins/stream-video-playerStream Video Player for WordPress its one stop solution for high quality video publishing for web or iOS.
Is Stream Video Player Safe to Use in 2026?
Use With Caution
Score 63/100Stream Video Player has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "stream-video-player" plugin v1.4.1 presents a mixed security posture. On the positive side, the static analysis reveals a notably small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events that are exposed without authentication or permission checks. SQL queries are exclusively handled via prepared statements, and there are some capability checks in place. However, several significant concerns emerge. A critical weakness is the extremely low rate of proper output escaping, with only 1% of 73 outputs being escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. The presence of 3 unsanitized path flows in the taint analysis, though not currently rated as critical or high, warrants attention as it could lead to path traversal vulnerabilities. The plugin also makes external HTTP requests and performs file operations, which, when combined with poor output escaping, can be dangerous.
The vulnerability history is a major red flag. With one high-severity, unpatched CVE from 2014, and the common vulnerability type being Cross-Site Request Forgery (CSRF), this suggests a pattern of past security weaknesses that have not been adequately addressed. The age of the last vulnerability also means it's unlikely to have benefited from modern WordPress security best practices. While the lack of a large, unprotected attack surface is a strength, the pervasive issue with output escaping and the unpatched historical vulnerability significantly outweigh this. The plugin is not recommended for use in a production environment without substantial security remediation.
Key Concerns
- 1 unpatched high severity CVE
- 1% properly escaped outputs (73 total)
- 3 flows with unsanitized paths
- Bundled library: TinyMCE (potential for outdated version)
- 0 Nonce checks
Stream Video Player Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Stream Video Player <= 1.4.1 - Cross-Site Request Forgery
Stream Video Player Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Stream Video Player Attack Surface
WordPress Hooks 15
Maintenance & Trust
Stream Video Player Maintenance & Trust
Maintenance Signals
Community Trust
Stream Video Player Alternatives
Podcast Searcher by Clarify
podcast-searcher-by-clarify
The Clarify plugin allows you to make any audio or video embedded in your posts, pages, etc searchable via the standard WordPress search box.
WP-SWFObject
wp-swfobject
Insert Flash Movies into WordPress.
All-in-One Video Gallery
all-in-one-video-gallery
The ultimate video player & video gallery plugin for YouTubers, Video Bloggers, Course Creators, Podcasters, and anyone embedding videos on websites.
Easy Video Player
easy-video-player
Easy Video Player is a WordPress video player that allows you to add videos to your WordPress site.
HTML5 Video Player – Embed and Play Videos in Custom Player
html5-video-player
HTML5 Video Player Plugin lets you embed responsive videos in WordPress. It’s easy to use, fast, and supports MP4, WebM, OGG, FLV, Youtube and Vimeo.
Stream Video Player Developer Profile
1 plugin · 700 total installs
How We Detect Stream Video Player
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/stream-video-player/css/style.css/wp-content/plugins/stream-video-player/js/swfobject.js/wp-content/plugins/stream-video-player/js/jplayer/jquery.jplayer.min.js/wp-content/plugins/stream-video-player/js/jplayer/jplayer.playlist.min.js/wp-content/plugins/stream-video-player/js/jwplayer.js/wp-content/plugins/stream-video-player/js/flvplayer.js/wp-content/plugins/stream-video-player/js/swfobject.js/wp-content/plugins/stream-video-player/js/jplayer/jquery.jplayer.min.js/wp-content/plugins/stream-video-player/js/jplayer/jplayer.playlist.min.js/wp-content/plugins/stream-video-player/js/jwplayer.js/wp-content/plugins/stream-video-player/js/flvplayer.jsstream-video-player/css/style.css?ver=stream-video-player/js/swfobject.js?ver=stream-video-player/js/jplayer/jquery.jplayer.min.js?ver=stream-video-player/js/jplayer/jplayer.playlist.min.js?ver=stream-video-player/js/jwplayer.js?ver=stream-video-player/js/flvplayer.js?ver=HTML / DOM Fingerprints
videoWrapperwideScreen<!--[if !IE]><!--><!--<![endif]-->data-swfdata-flvdata-mp4data-ogvdata-iddata-name+8 morejwplayerflowplayer[stream][/stream]