Video Reviews / Video Widget Security & Risk Analysis

wordpress.org/plugins/video-reviews

Transform your website with engaging video content. Add a powerful Video Reviews widget to your footer and boost conversions instantly.

100 active installs v1.5.4 PHP 5.6+ WP 4.0+ Updated Dec 14, 2024
lightboxvideo-lightboxvideo-popupvideo-reviewsyoutube-lightbox
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Video Reviews / Video Widget Safe to Use in 2026?

Generally Safe

Score 92/100

Video Reviews / Video Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "video-reviews" plugin v1.5.4 exhibits a concerning security posture due to a significant unprotected entry point. While the plugin demonstrates good practices by not using dangerous functions, performing all SQL queries with prepared statements, and having no recorded vulnerabilities, the presence of a single REST API route without permission callbacks represents a direct attack vector. This unprotected endpoint could potentially be leveraged for unauthorized actions or data manipulation if it handles any sensitive operations, even if not immediately apparent from the static analysis. The lack of nonce and capability checks on this route exacerbates the risk.

Despite the absence of known CVEs and a clean vulnerability history, which is a positive indicator of developer diligence, the static analysis highlights a critical oversight in its exposed REST API. The 50% output escaping rate also suggests potential for cross-site scripting (XSS) vulnerabilities if the unescaped outputs involve user-controlled data. In conclusion, while the plugin has strengths in its SQL handling and lack of historical issues, the unprotected REST API endpoint is a major weakness that requires immediate attention to mitigate potential security risks.

Key Concerns

  • REST API route without permission callbacks
  • Unescaped output rate is 50%
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Video Reviews / Video Widget Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Video Reviews / Video Widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
16
16 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Freemius1.0

Output Escaping

50% escaped32 total outputs
Attack Surface
1 unprotected

Video Reviews / Video Widget Attack Surface

Entry Points1
Unprotected1

REST API Routes 1

POST/wp-json/vdrv/v1/widgetVideoReviewsInit.php:44
WordPress Hooks 11
actionadmin_menuincludes\VDRVSettings.php:17
actionadmin_initincludes\VDRVSettings.php:18
actionadmin_enqueue_scriptsincludes\VDRVSettings.php:19
actionplugins_loadedVideoReviewsInit.php:29
actionplugins_loadedVideoReviewsInit.php:31
filternetwork_admin_plugin_action_links_video-reviews/video-reviews.phpVideoReviewsInit.php:33
filterplugin_action_links_video-reviews/video-reviews.phpVideoReviewsInit.php:34
actionadmin_initVideoReviewsInit.php:39
filtervdrv_get_widget_settingsVideoReviewsInit.php:41
actionrest_api_initVideoReviewsInit.php:43
actionwp_enqueue_scriptsVideoReviewsInit.php:120
Maintenance & Trust

Video Reviews / Video Widget Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedDec 14, 2024
PHP min version5.6
Downloads4K

Community Trust

Rating100/100
Number of ratings4
Active installs100
Developer Profile

Video Reviews / Video Widget Developer Profile

aharonyan

2 plugins · 200 total installs

59
trust score
Avg Security Score
72/100
Avg Patch Time
122 days
View full developer profile
Detection Fingerprints

How We Detect Video Reviews / Video Widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/video-reviews/build/admin.js/wp-content/plugins/video-reviews/build/adminStyle.css
Script Paths
video-reviews/build/admin.jsvideo-reviews/build/adminStyle.css
Version Parameters
video-reviews/build/admin.js?ver=video-reviews/build/adminStyle.css?ver=

HTML / DOM Fingerprints

CSS Classes
warning
Data Attributes
data-target
JS Globals
vd_rv
FAQ

Frequently Asked Questions about Video Reviews / Video Widget