VdoCipher: Secure Video Player and Hosting Security & Risk Analysis

wordpress.org/plugins/vdocipher

WordPress Video Player Plugin for VdoCipher: secure video embed, custom video player, watermark & easy integration with all LMS platforms.

2K active installs v1.30 PHP 5.6+ WP 3.5.1+ Updated Oct 12, 2025
drme-learningvideovideo-plugin
99
A · Safe
CVEs total1
Unpatched0
Last CVESep 30, 2024
Safety Verdict

Is VdoCipher: Secure Video Player and Hosting Safe to Use in 2026?

Generally Safe

Score 99/100

VdoCipher: Secure Video Player and Hosting has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Sep 30, 2024Updated 5mo ago
Risk Assessment

The vdocipher plugin v1.30 presents a generally good security posture with strong adherence to secure coding practices. The absence of critical or high severity taint flows, 100% usage of prepared statements for SQL queries, and a high percentage of properly escaped output are commendable. The presence of a capability check and the limited attack surface are also positive indicators. However, the plugin is not without its risks. The existence of a taint flow with unsanitized paths, even if not rated as critical or high, warrants attention as it represents a potential vector for vulnerabilities. Furthermore, the history of a medium severity Cross-Site Scripting (XSS) vulnerability, although currently patched, indicates a past weakness that could theoretically be reintroduced if code is not carefully maintained.

Key Concerns

  • Taint flow with unsanitized path
  • Past medium severity XSS vulnerability
  • 0 Nonce checks found
Vulnerabilities
1

VdoCipher: Secure Video Player and Hosting Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-47639medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

VdoCipher <= 1.29 - Authenticated (Contributor+) Stored Cross-Site Scripting

Sep 30, 2024 Patched in 1.30 (57d)
Code Analysis
Analyzed Mar 16, 2026

VdoCipher: Secure Video Player and Hosting Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
25 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

78% escaped32 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

2 flows1 with unsanitized paths
<options> (include\options.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

VdoCipher: Secure Video Player and Hosting Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[vdo] vdocipher.php:393
WordPress Hooks 5
actionplugins_loadedvdocipher.php:55
actionadmin_initvdocipher.php:410
actionadmin_menuvdocipher.php:411
actioninitvdocipher.php:525
actionadmin_noticesvdocipher.php:559
Maintenance & Trust

VdoCipher: Secure Video Player and Hosting Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedOct 12, 2025
PHP min version5.6
Downloads28K

Community Trust

Rating82/100
Number of ratings12
Active installs2K
Developer Profile

VdoCipher: Secure Video Player and Hosting Developer Profile

Vibhav Sinha

1 plugin · 2K total installs

87
trust score
Avg Security Score
99/100
Avg Patch Time
57 days
View full developer profile
Detection Fingerprints

How We Detect VdoCipher: Secure Video Player and Hosting

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/vdocipher/vdocipher-sdk.js/wp-content/plugins/vdocipher/vdocipher.js/wp-content/plugins/vdocipher/vdocipher_admin.js
Script Paths
https://player.vdocipher.com/v2/api.js

HTML / DOM Fingerprints

CSS Classes
vdo-player-wrapper
HTML Comments
<!-- VdoCipher Player START --><!-- VdoCipher Player END -->
Data Attributes
data-vdocipherdata-vdokeydata-vdoid
JS Globals
VdoPlayervdo
REST Endpoints
/wp-json/vdocipher/v1/get_video_details
Shortcode Output
[vdo-player vdo=
FAQ

Frequently Asked Questions about VdoCipher: Secure Video Player and Hosting