
Video Expander Security & Risk Analysis
wordpress.org/plugins/video-expanderyoutube video gallery, no lightbox video gallery, video grid Requires at least: 3.6 Tested up to: 4.3.1 Stable tag: 1.0 License: GPLv2 or later Licens …
Is Video Expander Safe to Use in 2026?
Mostly Safe
Score 78/100Video Expander is generally safe to use. 1 past CVE were resolved. Keep it updated.
The video-expander plugin v1.0 presents a mixed security posture. While it exhibits some good practices, such as using prepared statements for all SQL queries and having a relatively small attack surface with no readily apparent unprotected entry points in the static analysis, significant concerns remain. The presence of the `unserialize` function is a major red flag, as it can lead to Remote Code Execution if an attacker can control the serialized data input. Compounding this, a considerable portion of output is not properly escaped, increasing the risk of Cross-Site Scripting (XSS) vulnerabilities. The plugin's vulnerability history is also concerning, with one known medium-severity CVE related to XSS that is currently unpatched. This indicates a recurring security weakness that has not been addressed. The lack of nonce and capability checks on potential entry points further weakens its defense. While the plugin does not have a large attack surface or obvious unprotected REST API routes, the identified weaknesses in handling serialized data and output escaping, combined with an unpatched vulnerability, suggest a medium to high risk for installations.
Key Concerns
- Unpatched CVE detected
- Presence of unserialize function
- Insufficient output escaping
- No nonce checks detected
- No capability checks detected
Video Expander Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Video Expander <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
Video Expander Code Analysis
Dangerous Functions Found
Output Escaping
Video Expander Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
Video Expander Maintenance & Trust
Maintenance Signals
Community Trust
Video Expander Alternatives
Modula Image Gallery – Photo Grid & Video Gallery
modula-best-grid-gallery
Create responsive image galleries with drag-and-drop grid builder. Custom layouts, video support, AI optimization. Works with any theme.
Mixed Media Gallery Blocks
simply-gallery-block
Create mixed media galleries with images, HTML5 video, YouTube, Vimeo, and VideoPress — all in one gallery by Simply Gallery.
All-in-One Video Gallery
all-in-one-video-gallery
The ultimate video player & video gallery plugin for YouTubers, Video Bloggers, Course Creators, Podcasters, and anyone embedding videos on websites.
Video Gallery – YouTube Gallery, Vimeo, Video Portfolio, Image Portfolio and Image Gallery
gallery-videos
Gallery is a user-friendly plugin to display user or hashtag-based gallery feeds as a responsive customizable gallery.
Videopack
video-embed-thumbnail-generator
Makes video thumbnails, allows resolution switching, and embeds responsive self-hosted videos and galleries.
Video Expander Developer Profile
3 plugins · 40 total installs
How We Detect Video Expander
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/video-expander/js/video-expander.js/wp-content/plugins/video-expander/css/video-expander.css/wp-content/plugins/video-expander/assets/play-button.png/wp-content/plugins/video-expander/js/video-expander.jsvideo-expander/js/video-expander.js?ver=1.0.0HTML / DOM Fingerprints
video-itemplay-buttonvideo-captiondata-videodata-columns<div class="video-item" data-video="" data-columns="" style="background-image: url();"><div class="play-button" style="background: transparent url(