Video Thumbnails Reloaded Security & Risk Analysis
wordpress.org/plugins/video-thumbnails-reloadedVideo Thumbnails simplifies the process of automatically displaying video thumbnails in your WordPress template.
Is Video Thumbnails Reloaded Safe to Use in 2026?
Generally Safe
Score 85/100Video Thumbnails Reloaded has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'video-thumbnails-reloaded' plugin version 1.0.1 exhibits a generally good security posture with no recorded vulnerabilities or critical taint flows. All identified entry points, including AJAX handlers, lack explicit authorization checks, which is a significant concern. While the static analysis indicates 8 nonce and 8 capability checks across its 9 AJAX handlers, the absence of explicit "without auth checks" for any AJAX handler suggests these checks might not be universally applied or are potentially bypassable. The presence of the `unserialize` function twice is a notable risk, as it can lead to arbitrary object injection if not handled with extreme care and input validation. The plugin also uses raw SQL queries without prepared statements, increasing the risk of SQL injection. With a large number of external HTTP requests (25), there's also a potential for supply chain attacks or insecure handling of responses. Despite the absence of known CVEs and successful taint analysis, the identified code-level risks warrant attention.
Key Concerns
- AJAX handlers without explicit auth checks
- Use of unserialize() function
- SQL queries without prepared statements
- Low percentage of properly escaped output
- High number of external HTTP requests
Video Thumbnails Reloaded Security Vulnerabilities
Video Thumbnails Reloaded Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Video Thumbnails Reloaded Attack Surface
AJAX Handlers 9
WordPress Hooks 40
Maintenance & Trust
Video Thumbnails Reloaded Maintenance & Trust
Maintenance Signals
Community Trust
Video Thumbnails Reloaded Alternatives
The Ultimate Video Player For WordPress – by Presto Player
presto-player
The Ultimate WordPress Video Player.
All-in-One Video Gallery
all-in-one-video-gallery
The ultimate video player & video gallery plugin for YouTubers, Video Bloggers, Course Creators, Podcasters, and anyone embedding videos on websites.
WP Video Popup – WordPress Video Lightbox for YouTube, Rumble & Vimeo
responsive-youtube-vimeo-popup
WP Video Popup lets you add a responsive YouTube, Rumble or Vimeo video lightbox to any page, post or custom post type of your website.
Automatic Featured Images from Videos
automatic-featured-images-from-videos
If a YouTube or Vimeo video embed exists near the start of a post, we'll automatically set the post's featured image to a thumbnail of the video.
WPC Product Videos for WooCommerce
wpc-product-videos
WPC Product Videos helps you add many videos for a product and linked to the feature image or product gallery images.
Video Thumbnails Reloaded Developer Profile
6 plugins · 2K total installs
How We Detect Video Thumbnails Reloaded
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/video-thumbnails-reloaded/js/bulk.js/wp-content/plugins/video-thumbnails-reloaded/css/bulk.cssvideo-thumbnails-reloaded/js/bulk.js?ver=video-thumbnails-reloaded/css/bulk.css?ver=HTML / DOM Fingerprints
video-thumbnails-resetdata-iddata-securityvideo_thumbnails_bulk_language