
StreamNexus.io Embed Videos Security & Risk Analysis
wordpress.org/plugins/streamnexus-io-embed-videosEasily embed StreamNexus.io hosted videos using a shortcode. The plugin embeds an HTML5 ABR HLS video player.
Is StreamNexus.io Embed Videos Safe to Use in 2026?
Generally Safe
Score 100/100StreamNexus.io Embed Videos has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The streamnexus-io-embed-videos plugin v2.2.2 exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, SQL injection vulnerabilities (all queries use prepared statements), file operations, and external HTTP requests is commendable. The limited attack surface of a single shortcode with a capability check further contributes to its security. However, a significant concern arises from the output escaping. With 60% properly escaped, this means 40% of the 20 outputs are not, leaving potential room for cross-site scripting (XSS) vulnerabilities if user-supplied data is not sanitized before being displayed.
The plugin has no recorded vulnerability history, which is a positive indicator of ongoing security diligence. The lack of any critical or high-severity taint flows also suggests that the codebase is relatively clean concerning complex attack vectors. Despite the positive historical data and lack of critical static analysis findings, the identified output escaping deficiency warrants attention. This issue, while not critical on its own, can become a significant risk if an attacker can leverage it to inject malicious scripts into the WordPress site.
In conclusion, the plugin demonstrates good security practices in several key areas, particularly regarding data handling and external interactions. The absence of historical vulnerabilities is a significant strength. The primary area for improvement is the inconsistent output escaping. Addressing the unescaped outputs would further solidify the plugin's security and mitigate potential XSS risks.
Key Concerns
- Inconsistent output escaping (40% unescaped)
StreamNexus.io Embed Videos Security Vulnerabilities
StreamNexus.io Embed Videos Release Timeline
StreamNexus.io Embed Videos Code Analysis
Output Escaping
StreamNexus.io Embed Videos Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
StreamNexus.io Embed Videos Maintenance & Trust
Maintenance Signals
Community Trust
StreamNexus.io Embed Videos Alternatives
PlayerJS
playerjs
The official plugin for PlayerJS.com - video & audio player builder. Make an awesome player for your website for free.
AudioIgniter Music Player
audioigniter
AudioIgniter lets you create music playlists and embed them in your WordPress posts, pages or custom post types and serve your audio content in style!
CP Media Player – Audio Player and Video Player
audio-and-video-player
CP Media Player - Audio and Video Player supported by major browsers, such as IE, Firefox, Opera, Safari, Chrome, and mobile devices: iPhone, iPad, An …
Lean Player – Video and Audio Player for WordPress, Elementor, Block Editor and Classic Editor
az-video-and-audio-player-addon-for-elementor
WordPress Video Player & Audio Player plugin - simple, lightweight and customizable HTML5, YouTube, Vimeo & mp3 media player that supports all devices
FV Player 8
fv-player
WordPress's most reliable, easy to use and feature-rich video player. Supports playlists, ads, stats and user video position saving.
StreamNexus.io Embed Videos Developer Profile
1 plugin · 0 total installs
How We Detect StreamNexus.io Embed Videos
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/streamnexus-io-embed-videos/css/streamnexus.css/wp-content/plugins/streamnexus-io-embed-videos/js/streamnexus.js/wp-content/plugins/streamnexus-io-embed-videos/js/streamnexus.jsstreamnexus-io-embed-videos/css/streamnexus.css?ver=streamnexus-io-embed-videos/js/streamnexus.js?ver=HTML / DOM Fingerprints
streamnexus-video-containerfixed-heightdata-media-iddata-snx-autoratiostreamnexus_ajaxstreamnexus_ajax.ajax_urlstreamnexus_ajax.noncestreamnexus_ajax.i18nstreamnexus_ajax.i18n.unavailablestreamnexus_ajax.i18n.ajax_error<div class="streamnexus-video-containerdata-media-iddata-snx-autoratiostyle="position:relative; overflow:hidden;