Video Blogster Lite Security & Risk Analysis

wordpress.org/plugins/video-blogster-lite

Create a video blog in minutes! This plugin searches YouTube for content and automatically creates posts from the results.

800 active installs v1.2 PHP + WP 3.0+ Updated May 15, 2023
oembedvideo-blogvideoblogyou-tubeyoutube
42
D · High Risk
CVEs total2
Unpatched2
Last CVESep 26, 2025
Safety Verdict

Is Video Blogster Lite Safe to Use in 2026?

High Risk

Score 42/100

Video Blogster Lite carries significant security risk with 2 known CVEs, 2 still unpatched. Consider switching to a maintained alternative.

2 known CVEs 2 unpatched Last CVE: Sep 26, 2025Updated 2yr ago
Risk Assessment

The video-blogster-lite v1.2 plugin exhibits a mixed security posture. While it demonstrates some good practices, such as using prepared statements for all SQL queries, there are significant areas of concern. The lack of any identified nonce checks or capability checks on the entry points, combined with a concerning taint analysis result indicating a flow with unsanitized paths, suggests a potential for vulnerabilities, especially in the absence of a broad attack surface being exposed. The plugin's history of known vulnerabilities, including two currently unpatched medium severity issues of Cross-Site Request Forgery and Cross-Site Scripting, further amplifies the risk. These historical patterns, particularly the types of vulnerabilities, point towards potential weaknesses in input validation and output sanitization that have not been fully addressed.

Despite the positive aspects of secure SQL handling, the unpatched vulnerabilities and the findings from the static and taint analysis are substantial red flags. The 25% proper output escaping is also a weak signal. The absence of a larger attack surface is fortunate, but it does not negate the existing risks. The conclusion is that while the plugin has some secure foundations, the unpatched vulnerabilities and the identified code analysis concerns create a notable risk that requires immediate attention.

Key Concerns

  • Unpatched medium severity CVEs (2)
  • No nonce checks found
  • No capability checks found
  • Taint flow with unsanitized paths
  • Low percentage of properly escaped output
Vulnerabilities
2

Video Blogster Lite Security Vulnerabilities

CVEs by Year

2 CVEs in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2025-60132medium · 4.3Cross-Site Request Forgery (CSRF)

Video Blogster Lite <= 1.2 - Cross-Site Request Forgery

Sep 26, 2025Unpatched
CVE-2025-47689medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Video Blogster Lite <= 1.2 - Reflected Cross-Site Scripting

Jul 23, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

Video Blogster Lite Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
15
5 escaped
Nonce Checks
0
Capability Checks
0
File Operations
3
External Requests
1
Bundled Libraries
0

Output Escaping

25% escaped20 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<video-feed> (templates\video-feed.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Video Blogster Lite Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionadmin_enqueue_scriptsvideo-blogster-lite.php:32
actionadmin_menuvideo-blogster-lite.php:33
Maintenance & Trust

Video Blogster Lite Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedMay 15, 2023
PHP min version
Downloads23K

Community Trust

Rating100/100
Number of ratings5
Active installs800
Developer Profile

Video Blogster Lite Developer Profile

johnh10

2 plugins · 810 total installs

74
trust score
Avg Security Score
71/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Video Blogster Lite

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/video-blogster-lite/video-blogster-lite.css
Version Parameters
video-blogster-lite/video-blogster-lite.css?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Video Blogster Lite