HTML5 Webcam/Screen/Mic Recorder for Video Comments and Forms Security & Risk Analysis

wordpress.org/plugins/video-comments-webcam-recorder

Easily add webcam, screen, and mic recordings to WordPress comments and forms with this shortcode-enabled plugin for video and audio submissions.

60 active installs v2.2.6 PHP 7.4+ WP 5.0+ Updated Apr 1, 2025
commentshtml5recordervideowhisperwebcam
92
A · Safe
CVEs total1
Unpatched0
Last CVEJun 12, 2014
Safety Verdict

Is HTML5 Webcam/Screen/Mic Recorder for Video Comments and Forms Safe to Use in 2026?

Generally Safe

Score 92/100

HTML5 Webcam/Screen/Mic Recorder for Video Comments and Forms has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Jun 12, 2014Updated 1yr ago
Risk Assessment

The "video-comments-webcam-recorder" plugin version 2.2.6 exhibits a mixed security posture. While it demonstrates good practices in handling SQL queries and output escaping, significant concerns arise from its unprotected entry points and the presence of a dangerous function. Specifically, the analysis reveals two AJAX handlers lacking authentication checks, which can expose the plugin to unauthorized actions. The presence of the `unserialize` function, a known risk if not handled with extreme care and input validation, also warrants attention.

The plugin's vulnerability history indicates a single medium-severity CVE related to Cross-Site Scripting, last recorded in 2014. The fact that this vulnerability is currently patched is a positive sign, but the historical presence of XSS highlights a past weakness in input sanitization or output escaping in certain contexts. The absence of critical or high-severity taint flows is encouraging, suggesting that current versions might have mitigated more severe code execution risks.

Overall, the plugin has strengths in its SQL query preparation and output escaping. However, the critical weakness of unprotected AJAX handlers presents a tangible risk of unauthorized access and potential exploitation. The historical XSS vulnerability, though patched, serves as a reminder of the importance of robust input validation. Users should be aware of these potential attack vectors when using this plugin.

Key Concerns

  • 2 AJAX handlers without auth checks
  • Dangerous function 'unserialize' present
  • 1 medium CVE historically, though patched
Vulnerabilities
1

HTML5 Webcam/Screen/Mic Recorder for Video Comments and Forms Security Vulnerabilities

CVEs by Year

1 CVE in 2014
2014
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2014-4567medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

HTML5 Webcam Microphone Recorder Forms < 1.55 - Cross-Site Scripting

Jun 12, 2014 Patched in 1.55.3 (3512d)
Code Analysis
Analyzed Mar 16, 2026

HTML5 Webcam/Screen/Mic Recorder for Video Comments and Forms Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
0 prepared
Unescaped Output
3
42 escaped
Nonce Checks
1
Capability Checks
2
File Operations
2
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

unserialize'appSetup' => unserialize('a:1:{s:6:"Config";a:12:{s:8:"darkMode";s:0:"";s:16:"resolutionHeight";s:3inc\options.php:146

Output Escaping

93% escaped45 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
adminOptions (inc\options.php:222)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

HTML5 Webcam/Screen/Mic Recorder for Video Comments and Forms Attack Surface

Entry Points3
Unprotected2

AJAX Handlers 2

authwp_ajax_vw_irec_appinlinerecorder.php:49
noprivwp_ajax_vw_irec_appinlinerecorder.php:50

Shortcodes 1

[videowhisper_recorder_inline] inlinerecorder.php:46
WordPress Hooks 6
filtercomment_form_defaultsinlinerecorder.php:59
actioncomment_postinlinerecorder.php:60
filterget_comment_textinlinerecorder.php:61
actionplugins_loadedinlinerecorder.php:147
actionadmin_menuinlinerecorder.php:148
actionadmin_bar_menuinlinerecorder.php:149
Maintenance & Trust

HTML5 Webcam/Screen/Mic Recorder for Video Comments and Forms Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedApr 1, 2025
PHP min version7.4
Downloads13K

Community Trust

Rating0/100
Number of ratings0
Active installs60
Developer Profile

HTML5 Webcam/Screen/Mic Recorder for Video Comments and Forms Developer Profile

videowhisper

12 plugins · 1K total installs

74
trust score
Avg Security Score
93/100
Avg Patch Time
1072 days
View full developer profile
Detection Fingerprints

How We Detect HTML5 Webcam/Screen/Mic Recorder for Video Comments and Forms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/video-comments-webcam-recorder/css/style.css/wp-content/plugins/video-comments-webcam-recorder/js/videowhisper_recorder_inline.js
Script Paths
https://cdn.jsdelivr.net/npm/fomantic-ui@2.8.7/dist/semantic.min.js//cdn.jsdelivr.net/npm/semantic-ui@2.4.2/d
Version Parameters
video-comments-webcam-recorder/css/style.css?ver=video-comments-webcam-recorder/js/videowhisper_recorder_inline.js?ver=

HTML / DOM Fingerprints

CSS Classes
vw_recorder_inlinevw_recorder_inline_field
Data Attributes
data-fielddata-add_fielddata-label
JS Globals
VideoWhisper
REST Endpoints
/wp-json/vw_recorder_inline/v1
Shortcode Output
[videowhisper_recorder_inline]
FAQ

Frequently Asked Questions about HTML5 Webcam/Screen/Mic Recorder for Video Comments and Forms