
Video and Audio BBCodes Security & Risk Analysis
wordpress.org/plugins/video-audio-bbcodesThis plugin adds support for video and audio shortcodes to posts and pages. If you have 'bbPress2 shortcode whitelist' installed, you can al …
Is Video and Audio BBCodes Safe to Use in 2026?
Generally Safe
Score 85/100Video and Audio BBCodes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "video-audio-bbcodes" v1.1 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of known CVEs and a clean vulnerability history are positive indicators. The code analysis shows a notable strength in SQL query sanitization, with all queries utilizing prepared statements, and all output being properly escaped, significantly mitigating common web vulnerabilities like SQL injection and cross-site scripting (XSS).
However, the static analysis reveals two critical "dangerous functions" being used: `unserialize` and `create_function`. The use of `unserialize` is a significant concern, as it can lead to Remote Code Execution (RCE) if untrusted data is passed to it. The `create_function` is also considered dangerous as it allows for arbitrary code execution, although its risk is often mitigated by careful usage. The plugin also lacks nonce checks and only has one capability check across its 12 entry points (shortcodes). This means that while output is escaped, the functionality triggered by shortcodes might be accessible and exploitable by unauthenticated users if the dangerous functions are called with user-controlled input. The absence of taint analysis results is also a limitation, as it prevents a deeper understanding of how data flows and if these dangerous functions are actually exposed to malicious input.
In conclusion, while the plugin demonstrates good practices in output escaping and SQL handling, the presence of `unserialize` and `create_function` without clear evidence of input validation or authorization checks for the data they process presents a substantial risk. The lack of nonce checks and minimal capability checks further exacerbates this risk. The clean vulnerability history is encouraging, but it does not negate the inherent dangers of the identified code signals. Further manual code review focusing on the implementation of `unserialize` and `create_function` and how they handle user input is highly recommended.
Key Concerns
- Use of unserialize function
- Use of create_function
- No nonce checks on entry points
- Minimal capability checks
Video and Audio BBCodes Security Vulnerabilities
Video and Audio BBCodes Code Analysis
Dangerous Functions Found
Output Escaping
Video and Audio BBCodes Attack Surface
Shortcodes 12
WordPress Hooks 2
Maintenance & Trust
Video and Audio BBCodes Maintenance & Trust
Maintenance Signals
Community Trust
Video and Audio BBCodes Alternatives
bbPress2 BBCode
bbpress-bbcode
This plugin adds support for popular bbcode forum code to posts, comments, pages, bbpress 2.0 forums and buddypress activity and group forums.
GD bbPress Tools
gd-bbpress-tools
Adds different expansions and tools to the bbPress plugin powered forums: BBCode support, signatures, various tweaks, custom views, quote...
CBX User Online & Last Login
cbxuseronline
Shows online users based on cookie for guest and session for registered user. It also records the last login of user.
WP Notification Bell
wp-notification-bell
On-site bell notifications. Display notifications custom or triggered (new posts/cpts, WooCommerce order updates, new comment replies, bbPress...)
bbPress Login Register Links On Forum Topic Pages
bbpress-login-register-links-on-forum-topic-pages
Add bbPress only sidebar, Add bbpress login link, bbpress register link, forget password link, log out link in bbpress forum index pages or bbpress si …
Video and Audio BBCodes Developer Profile
3 plugins · 120 total installs
How We Detect Video and Audio BBCodes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/video-audio-bbcodes/video-audio-bbcodes-admin.php/wp-content/plugins/video-audio-bbcodes/class_video-audio-bbcodes.phpHTML / DOM Fingerprints
GPL3 This program is free software: you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation, either version 3 of the License, or+7 moreframeborderscrollingsrcwidthheight<iframe frameborder="0" scrolling="no" src="http://www.freesound.org/embed/sound/iframe//simple/large/" width="920" height="245"></iframe>/simple/small/" width="375" height="30"></iframe>/simple/medium/" width="481" height="86"></iframe>