Video Player for WPBakery Security & Risk Analysis

wordpress.org/plugins/video-player-for-wpbakery

Video Player for WPBakery add-on for WPBakery Page Builder allow add YouTube, Vimeo and Self-Hosted videos (HTML5) to your WordPress website.

2K active installs v1.1.0 PHP 7.4+ WP 5.7+ Updated Feb 19, 2026
html5self-hosted-videovideo-playervideo-player-for-wpbakery
99
A · Safe
CVEs total1
Unpatched0
Last CVENov 28, 2024
Safety Verdict

Is Video Player for WPBakery Safe to Use in 2026?

Generally Safe

Score 99/100

Video Player for WPBakery has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Nov 28, 2024Updated 1mo ago
Risk Assessment

The "video-player-for-wpbakery" v1.1.0 plugin exhibits a generally strong security posture based on the static analysis. The complete absence of dangerous functions, reliance on prepared statements for all SQL queries, and 100% output escaping are excellent security practices. Furthermore, the lack of file operations, external HTTP requests, and the indication of no unsanitized taint flows suggest a well-contained and secure codebase in these areas. The limited attack surface, with only one shortcode and no unprotected AJAX handlers or REST API routes, further bolsters its security.

However, the vulnerability history is a significant concern. While there are no currently unpatched vulnerabilities, the plugin has a past CVE associated with Cross-site Scripting (XSS). The fact that the last vulnerability was recently disclosed (2024-11-28) suggests that past issues may not have been fully addressed or that the plugin might be a target for finding such vulnerabilities. The absence of nonce and capability checks, while not immediately exploitable given the current analysis of entry points, represents a potential weakness that could be leveraged if new entry points or vulnerabilities are introduced in future versions or if existing ones are found to be more permissive than initially assessed.

In conclusion, the current version of the plugin demonstrates good coding practices in static analysis, indicating robust protection against common vulnerabilities. Nevertheless, the historical presence of an XSS vulnerability, even if patched, warrants vigilance, especially given its recent disclosure. The lack of explicit nonce and capability checks on the identified entry point (shortcode) could be a point of future concern if not addressed.

Key Concerns

  • Past medium severity CVE (XSS)
  • 0 Nonce checks found
  • 0 Capability checks found
Vulnerabilities
1

Video Player for WPBakery Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-53747medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Video Player for WPBakery <= 1.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

Nov 28, 2024 Patched in 1.0.2 (203d)
Code Analysis
Analyzed Mar 16, 2026

Video Player for WPBakery Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
37 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped37 total outputs
Attack Surface

Video Player for WPBakery Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[video_player_for_wpbakery] video-player-for-wpbakery.php:65
WordPress Hooks 5
actionwp_enqueue_scriptsvideo-player-for-wpbakery.php:60
actionadmin_enqueue_scriptsvideo-player-for-wpbakery.php:61
actionvc_load_default_paramsvideo-player-for-wpbakery.php:62
actionvc_before_initvideo-player-for-wpbakery.php:63
actionadmin_noticesvideo-player-for-wpbakery.php:67
Maintenance & Trust

Video Player for WPBakery Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 19, 2026
PHP min version7.4
Downloads12K

Community Trust

Rating74/100
Number of ratings3
Active installs2K
Developer Profile

Video Player for WPBakery Developer Profile

nutttaro

5 plugins · 5K total installs

79
trust score
Avg Security Score
100/100
Avg Patch Time
203 days
View full developer profile
Detection Fingerprints

How We Detect Video Player for WPBakery

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/video-player-for-wpbakery/assets/css/style.css/wp-content/plugins/video-player-for-wpbakery/assets/js/admin-script.min.js/wp-content/plugins/video-player-for-wpbakery/assets/css/admin-style.css
Version Parameters
video-player-for-wpbakery/assets/css/style.css?ver=video-player-for-wpbakery/assets/js/admin-script.min.js?ver=video-player-for-wpbakery/assets/css/admin-style.css?ver=

HTML / DOM Fingerprints

CSS Classes
video-player-for-wpbakeryvideo-player-for-wpbakery-typevideo-player-for-wpbakery-videovideo-player-for-wpbakery-video_idvideo-player-for-wpbakery-video_url
Data Attributes
data-param-typedata-param-videodata-param-video_iddata-param-video_urldata-param-widthdata-param-height+5 more
JS Globals
window.video_player_for_wpbakery_data
Shortcode Output
[video_player_for_wpbakery
FAQ

Frequently Asked Questions about Video Player for WPBakery