VdoCipher: Secure Video Player and Hosting Security & Risk Analysis

wordpress.org/plugins/vdocipher

WordPress Video Player Plugin for VdoCipher: secure video embed, custom video player, watermark & easy integration with all LMS platforms.

2K active installs v1.30 PHP 5.6+ WP 3.5.1+ Updated Oct 12, 2025
drme-learningvideovideo-plugin
99
A · Safe
CVEs total1
Unpatched0
Last CVESep 30, 2024
Safety Verdict

Is VdoCipher: Secure Video Player and Hosting Safe to Use in 2026?

Generally Safe

Score 99/100

VdoCipher: Secure Video Player and Hosting has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Sep 30, 2024Updated 7mo ago
Risk Assessment

The vdocipher plugin v1.30 presents a generally good security posture with strong adherence to secure coding practices. The absence of critical or high severity taint flows, 100% usage of prepared statements for SQL queries, and a high percentage of properly escaped output are commendable. The presence of a capability check and the limited attack surface are also positive indicators. However, the plugin is not without its risks. The existence of a taint flow with unsanitized paths, even if not rated as critical or high, warrants attention as it represents a potential vector for vulnerabilities. Furthermore, the history of a medium severity Cross-Site Scripting (XSS) vulnerability, although currently patched, indicates a past weakness that could theoretically be reintroduced if code is not carefully maintained.

Key Concerns

  • Taint flow with unsanitized path
  • Past medium severity XSS vulnerability
  • 0 Nonce checks found
Vulnerabilities
1 published

VdoCipher: Secure Video Player and Hosting Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-47639medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

VdoCipher <= 1.29 - Authenticated (Contributor+) Stored Cross-Site Scripting

Sep 30, 2024 Patched in 1.30 (57d)
Version History

VdoCipher: Secure Video Player and Hosting Release Timeline

v1.30Current
v1.291 CVE
v1.281 CVE
v1.271 CVE
v1.261 CVE
v1.251 CVE
v1.241 CVE
v1.231 CVE
v1.221 CVE
v1.211 CVE
v1.201 CVE
v1.191 CVE
v1.181 CVE
v1.171 CVE
v1.151 CVE
v1.141 CVE
v1.131 CVE
v1.121 CVE
v1.111 CVE
v1.101 CVE
Code Analysis
Analyzed Mar 16, 2026

VdoCipher: Secure Video Player and Hosting Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
25 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

78% escaped32 total outputs
Data Flows · Security
1 unsanitized

Data Flow Analysis

2 flows1 with unsanitized paths
<options> (include\options.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

VdoCipher: Secure Video Player and Hosting Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[vdo] vdocipher.php:393
WordPress Hooks 5
actionplugins_loadedvdocipher.php:55
actionadmin_initvdocipher.php:410
actionadmin_menuvdocipher.php:411
actioninitvdocipher.php:525
actionadmin_noticesvdocipher.php:559
Maintenance & Trust

VdoCipher: Secure Video Player and Hosting Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedOct 12, 2025
PHP min version5.6
Downloads28K

Community Trust

Rating82/100
Number of ratings12
Active installs2K
Developer Profile

VdoCipher: Secure Video Player and Hosting Developer Profile

Vibhav Sinha

1 plugin · 2K total installs

87
trust score
Avg Security Score
99/100
Avg Patch Time
57 days
View full developer profile
Detection Fingerprints

How We Detect VdoCipher: Secure Video Player and Hosting

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/vdocipher/vdocipher-sdk.js/wp-content/plugins/vdocipher/vdocipher.js/wp-content/plugins/vdocipher/vdocipher_admin.js
Script Paths
https://player.vdocipher.com/v2/api.js

HTML / DOM Fingerprints

CSS Classes
vdo-player-wrapper
HTML Comments
<!-- VdoCipher Player START --><!-- VdoCipher Player END -->
Data Attributes
data-vdocipherdata-vdokeydata-vdoid
JS Globals
VdoPlayervdo
REST Endpoints
/wp-json/vdocipher/v1/get_video_details
Shortcode Output
[vdo-player vdo=
FAQ

Frequently Asked Questions about VdoCipher: Secure Video Player and Hosting