
SWFPut – SWFlash Put Security & Risk Analysis
wordpress.org/plugins/swfputSWFPut provides video players for posts and pages and widget areas, as both HTML5 and flash video.
Is SWFPut – SWFlash Put Safe to Use in 2026?
Generally Safe
Score 85/100SWFPut – SWFlash Put has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The swfput plugin v3.1.0.1 presents a mixed security profile. The static analysis reveals a commendable absence of direct attack vectors like unprotected AJAX handlers, REST API routes, or shortcodes. Furthermore, the plugin demonstrates good practices by exclusively using prepared statements for its SQL queries and employing a significant number of capability checks (18). However, a critical concern arises from the output escaping, with only 2% of 170 outputs being properly escaped. This indicates a substantial risk of Cross-Site Scripting (XSS) vulnerabilities, where user-supplied data, if not properly handled, could be injected and executed in the browser. The taint analysis also flagged one flow with an unsanitized path, which, while not critical or high severity, warrants attention as it represents a potential avenue for unauthorized file access or manipulation.
The plugin's vulnerability history is remarkably clean, with zero recorded CVEs. This lack of past vulnerabilities is a positive indicator, suggesting either a diligent development history or that the plugin's limited functionality hasn't attracted significant malicious attention. However, it is crucial not to solely rely on the absence of history. The identified output escaping issue and the unsanitized path flow in the static and taint analyses represent active, inherent risks that must be addressed independently of past security incidents. In conclusion, swfput shows strengths in its limited attack surface and SQL handling, but its weak output escaping and a single unsanitized path flow represent significant security weaknesses that require immediate remediation.
Key Concerns
- Low percentage of properly escaped output
- Unsanitized path in taint analysis
- No nonce checks
SWFPut – SWFlash Put Security Vulnerabilities
SWFPut – SWFlash Put Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
SWFPut – SWFlash Put Attack Surface
WordPress Hooks 16
Maintenance & Trust
SWFPut – SWFlash Put Maintenance & Trust
Maintenance Signals
Community Trust
SWFPut – SWFlash Put Alternatives
FV Flowplayer Video Player
fv-wordpress-flowplayer
WordPress's most reliable, easy to use and feature-rich video player. Supports responsive design, HTML5, playlists, ads, stats, Vimeo and YouTube.
HTML5 Video Player – Embed and Play Videos in Custom Player
html5-video-player
HTML5 Video Player Plugin lets you embed responsive videos in WordPress. It’s easy to use, fast, and supports MP4, WebM, OGG, FLV, Youtube and Vimeo.
FV Player 8
fv-player
WordPress's most reliable, easy to use and feature-rich video player. Supports playlists, ads, stats and user video position saving.
Fluid Player
fluid-player
The plugin makes it easy to embed the VAST ready Fluid Player video player.
WP Smart TV
wp-smart-tv
The ultimate toolkit for video streaming services using WordPress. Turn your site into an video service similar to YouTube or Vimeo.
SWFPut – SWFlash Put Developer Profile
2 plugins · 40 total installs
How We Detect SWFPut – SWFlash Put
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/swfput/js/formxed.min.js/wp-content/plugins/swfput/js/screens.min.js/wp-content/plugins/swfput/evhflv/obj.cssswfput/js/screens.min.js?ver=swfput/js/formxed.min.js?ver=HTML / DOM Fingerprints
<!-- html5 video/flash player -->data-swfput-vcenterdata-swfput-urldata-swfput-iddata-swfput-wdata-swfput-hdata-swfput-loop+9 morewindow.evhplg_ctl_textpair[putswf_video