Video Tab For WooCommerce Security & Risk Analysis

wordpress.org/plugins/video-tab-for-woocommerce

Plugin to add the new tab for video or additional content like contact forms, shortcodes, important features and other useful information to WooCommer …

700 active installs v1.0.1 PHP 5.2.0+ WP 4.5.0+ Updated Apr 28, 2018
custom-video-fieldvideo-tabvideo-tab-for-woocommerce-productswoocommerce-addonwoocommerce-video-tab
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Video Tab For WooCommerce Safe to Use in 2026?

Generally Safe

Score 85/100

Video Tab For WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The static analysis of the "video-tab-for-woocommerce" plugin v1.0.1 reveals a seemingly strong security posture with no identified vulnerabilities in code signals or taint analysis. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests are positive indicators. Furthermore, the plugin does not appear to expose a significant attack surface through AJAX, REST API, or shortcodes, which is commendable. The plugin also has no recorded vulnerability history, suggesting a good track record.

However, a closer examination of the code signals raises some concerns. The fact that there are no capability checks or nonce checks in place, despite having several output points that are not properly escaped, presents a potential risk. While the static analysis didn't flag specific taint flows related to these outputs, an attacker could potentially exploit unescaped output, especially if there were any indirect ways to inject malicious data. The lack of these fundamental security checks is a notable weakness that could be exploited in conjunction with other factors not immediately apparent from this analysis.

In conclusion, while the plugin demonstrates a clean slate regarding known vulnerabilities and avoids many common pitfalls like raw SQL, its security is weakened by the absence of essential authorization and integrity checks (capability and nonce checks). The partially unescaped output, combined with the lack of these checks, creates a latent risk. The plugin is currently strong on paper due to the lack of direct vulnerabilities found, but it has room for improvement in implementing robust security best practices for user input validation and access control.

Key Concerns

  • No capability checks found
  • No nonce checks found
  • Some output not properly escaped
Vulnerabilities
None known

Video Tab For WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Video Tab For WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
5 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

71% escaped7 total outputs
Attack Surface

Video Tab For WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
filterwoocommerce_product_data_tabscustom-video-tab\video-tab-admin.php:4
actionwoocommerce_product_data_panelscustom-video-tab\video-tab-admin.php:21
actionwoocommerce_process_product_metacustom-video-tab\video-tab-admin.php:71
actionadmin_headcustom-video-tab\video-tab-admin.php:137
filterwoocommerce_product_tabscustom-video-tab\video-tab-front.php:4
actionplugins_loadedvideo-tab-for-woocommerce.php:35
actionadmin_noticesvideo-tab-for-woocommerce.php:36
actionplugins_loadedvideo-tab-for-woocommerce.php:90
Maintenance & Trust

Video Tab For WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedApr 28, 2018
PHP min version5.2.0
Downloads39K

Community Trust

Rating0/100
Number of ratings0
Active installs700
Developer Profile

Video Tab For WooCommerce Developer Profile

ProDesigns

4 plugins · 2K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Video Tab For WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
vtfw-video-tab
Data Attributes
id='vtfw_custom_video_tab_data'
FAQ

Frequently Asked Questions about Video Tab For WooCommerce