VideoADShtml5 Security & Risk Analysis

wordpress.org/plugins/videoadshtml5

VideoADShtml5 is a WordPress video Player where you can insert ads on your WordPress site.

10 active installs v2.9 PHP + WP 5.3+ Updated Jan 13, 2026
adsplayerpre-rollvastvideo
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is VideoADShtml5 Safe to Use in 2026?

Generally Safe

Score 100/100

VideoADShtml5 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "videoadshtml5" v2.9 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, the exclusive use of prepared statements for SQL queries, and the complete output escaping suggest adherence to secure coding practices. Furthermore, the plugin has no recorded vulnerability history, including critical or high severity CVEs, which is a positive indicator. The limited attack surface, with only one shortcode and no unprotected entry points, further contributes to its perceived security.

However, there are notable concerns. The complete lack of nonce checks and capability checks is a significant weakness. While the static analysis didn't identify any direct exploitable flows, this absence of authorization and integrity checks on potential entry points like the shortcode means that malicious actors could potentially trigger plugin functionality in unintended ways or with unauthorized data. The file operations, although not explicitly detailed, could also pose a risk if not handled securely, especially in conjunction with the missing capability checks. The lack of external HTTP requests is a positive aspect, reducing the risk of supply chain attacks or content injection through external resources.

In conclusion, while the plugin demonstrates good practices in areas like SQL and output handling, the absence of critical security mechanisms like nonce and capability checks presents a substantial risk. This oversight creates potential vulnerabilities that could be exploited if a suitable attack vector is discovered, despite the current lack of recorded history or identified taint flows. Prioritizing the implementation of these checks would significantly improve the plugin's overall security.

Key Concerns

  • No nonce checks on entry points
  • No capability checks on entry points
  • Potential risk from file operations without checks
Vulnerabilities
None known

VideoADShtml5 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

VideoADShtml5 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
14 escaped
Nonce Checks
0
Capability Checks
0
File Operations
6
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped14 total outputs
Attack Surface

VideoADShtml5 Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[videoads] videoadshtml5.php:49
WordPress Hooks 8
actionplugins_loadedvideoadshtml5.php:46
actionwp_enqueue_scriptsvideoadshtml5.php:47
actionadmin_menuvideoadshtml5.php:48
filterwidget_textvideoadshtml5.php:50
filterthe_excerptvideoadshtml5.php:51
filterthe_contentvideoadshtml5.php:52
filterplugin_row_metavideoadshtml5.php:53
actionadmin_initvideoadshtml5.php:109
Maintenance & Trust

VideoADShtml5 Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 13, 2026
PHP min version
Downloads4K

Community Trust

Rating20/100
Number of ratings1
Active installs10
Developer Profile

VideoADShtml5 Developer Profile

saucykiss

2 plugins · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect VideoADShtml5

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/videoadshtml5/js/videoadshtml5.js/wp-content/plugins/videoadshtml5/css/videoadshtml5.css
Script Paths
/wp-content/plugins/videoadshtml5/js/videoadshtml5.js
Version Parameters
videoadshtml5/js/videoadshtml5.js?ver=videoadshtml5/css/videoadshtml5.css?ver=

HTML / DOM Fingerprints

CSS Classes
videoadshtml5_player
HTML Comments
<!-- VIDEO ADS HTML5 -->
Data Attributes
data-videoadshtml5-id
JS Globals
VideoADSHtml5Player
Shortcode Output
[videoads]
FAQ

Frequently Asked Questions about VideoADShtml5