
Embed videos and respect privacy Security & Risk Analysis
wordpress.org/plugins/video-embed-privacyAllows you to embed youtube videos without sending data to google on every page view.
Is Embed videos and respect privacy Safe to Use in 2026?
Generally Safe
Score 91/100Embed videos and respect privacy has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "video-embed-privacy" plugin v1.3 exhibits a mixed security posture. On the positive side, the static analysis indicates a very small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events that lack authentication. Furthermore, all SQL queries are properly prepared, and there are no identified critical or high-severity taint flows. The plugin also does not appear to make external HTTP requests or bundle external libraries, reducing its attack surface in those areas.
However, significant concerns arise from the output escaping and vulnerability history. The fact that 100% of the identified outputs are not properly escaped is a major red flag, indicating a high potential for Cross-Site Scripting (XSS) vulnerabilities. While there are no currently unpatched CVEs, the plugin has a history of a medium-severity XSS vulnerability, with the last recorded instance being very recent (October 2024). This pattern of XSS vulnerabilities, coupled with the lack of output escaping, suggests a recurring weakness in how the plugin handles user-supplied or dynamically generated content before it's displayed to the user.
In conclusion, while the plugin has strong points regarding its attack surface and SQL practices, the prevalent lack of output escaping and the recent history of XSS vulnerabilities represent critical weaknesses that require immediate attention. The potential for XSS is significantly elevated, and despite no current unpatched vulnerabilities, the pattern suggests a need for more robust input validation and output sanitization to prevent future exploits.
Key Concerns
- 100% of outputs unescaped
- Medium severity vulnerability history
- Recent vulnerability (2024-10-10)
- No capability checks found
- No nonce checks found
Embed videos and respect privacy Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Embed videos and respect privacy <= 1.2 - Reflected Cross-Site Scripting
Embed videos and respect privacy Release Timeline
Embed videos and respect privacy Code Analysis
Output Escaping
Embed videos and respect privacy Attack Surface
WordPress Hooks 2
Maintenance & Trust
Embed videos and respect privacy Maintenance & Trust
Maintenance Signals
Community Trust
Embed videos and respect privacy Alternatives
schmie_Wetter
weather-for-germany
Update 5.06.11
WP Live-Shopping Caroussel
wp-liveshopping-caroussel
Live-Shopping Caroussel
EmbedPress – PDF Embedder, Embed YouTube Videos, 3D FlipBook, Social feeds, Docs & more
embedpress
EmbedPress lets you embed videos, pages, social feeds, embed PDF 3D flipbooks & other content on WordPress without coding & enhance storytelling.
Feeds for YouTube (YouTube video, channel, and gallery plugin)
feeds-for-youtube
The Feeds for YouTube plugin allows you to display customizable YouTube feeds from any YouTube channel.
The Ultimate Video Player For WordPress – by Presto Player
presto-player
The Ultimate WordPress Video Player.
Embed videos and respect privacy Developer Profile
2 plugins · 2K total installs
How We Detect Embed videos and respect privacy
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/video-embed-privacy/video-embed-privacy.css/wp-content/plugins/video-embed-privacy/video-embed-privacy.js/wp-content/plugins/video-embed-privacy/video-embed-privacy.jsvideo-embed-privacy.css?ver=video-embed-privacy.js?ver=HTML / DOM Fingerprints
video-wrappedvideo-wrapped-nojsdata-embed-framedata-embed-play