Embed videos and respect privacy Security & Risk Analysis

wordpress.org/plugins/video-embed-privacy

Allows you to embed youtube videos without sending data to google on every page view.

2K active installs v1.3 PHP + WP 4.5+ Updated Oct 10, 2024
deutschlandgermanyyoutube
91
A · Safe
CVEs total1
Unpatched0
Last CVEOct 10, 2024
Safety Verdict

Is Embed videos and respect privacy Safe to Use in 2026?

Generally Safe

Score 91/100

Embed videos and respect privacy has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Oct 10, 2024Updated 1yr ago
Risk Assessment

The "video-embed-privacy" plugin v1.3 exhibits a mixed security posture. On the positive side, the static analysis indicates a very small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events that lack authentication. Furthermore, all SQL queries are properly prepared, and there are no identified critical or high-severity taint flows. The plugin also does not appear to make external HTTP requests or bundle external libraries, reducing its attack surface in those areas.

However, significant concerns arise from the output escaping and vulnerability history. The fact that 100% of the identified outputs are not properly escaped is a major red flag, indicating a high potential for Cross-Site Scripting (XSS) vulnerabilities. While there are no currently unpatched CVEs, the plugin has a history of a medium-severity XSS vulnerability, with the last recorded instance being very recent (October 2024). This pattern of XSS vulnerabilities, coupled with the lack of output escaping, suggests a recurring weakness in how the plugin handles user-supplied or dynamically generated content before it's displayed to the user.

In conclusion, while the plugin has strong points regarding its attack surface and SQL practices, the prevalent lack of output escaping and the recent history of XSS vulnerabilities represent critical weaknesses that require immediate attention. The potential for XSS is significantly elevated, and despite no current unpatched vulnerabilities, the pattern suggests a need for more robust input validation and output sanitization to prevent future exploits.

Key Concerns

  • 100% of outputs unescaped
  • Medium severity vulnerability history
  • Recent vulnerability (2024-10-10)
  • No capability checks found
  • No nonce checks found
Vulnerabilities
1 published

Embed videos and respect privacy Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-9346medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Embed videos and respect privacy <= 1.2 - Reflected Cross-Site Scripting

Oct 10, 2024 Patched in 1.3 (1d)
Version History

Embed videos and respect privacy Release Timeline

v1.3Current
v1.21 CVE
v1.11 CVE
v1.01 CVE
Code Analysis
Analyzed Mar 16, 2026

Embed videos and respect privacy Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
2
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped1 total outputs
Attack Surface

Embed videos and respect privacy Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
filterembed_oembed_htmlvideo-embed-privacy.php:59
actionwp_enqueue_scriptsvideo-embed-privacy.php:60
Maintenance & Trust

Embed videos and respect privacy Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedOct 10, 2024
PHP min version
Downloads16K

Community Trust

Rating82/100
Number of ratings11
Active installs2K
Developer Profile

Embed videos and respect privacy Developer Profile

Michael Zangl

2 plugins · 2K total installs

92
trust score
Avg Security Score
88/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect Embed videos and respect privacy

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/video-embed-privacy/video-embed-privacy.css/wp-content/plugins/video-embed-privacy/video-embed-privacy.js
Script Paths
/wp-content/plugins/video-embed-privacy/video-embed-privacy.js
Version Parameters
video-embed-privacy.css?ver=video-embed-privacy.js?ver=

HTML / DOM Fingerprints

CSS Classes
video-wrappedvideo-wrapped-nojs
Data Attributes
data-embed-framedata-embed-play
FAQ

Frequently Asked Questions about Embed videos and respect privacy