
Featured Video for WordPress – VideographyWP Security & Risk Analysis
wordpress.org/plugins/videographywpWordPress featured video plugin that allows you to create video posts from YouTube videos.
Is Featured Video for WordPress – VideographyWP Safe to Use in 2026?
Generally Safe
Score 99/100Featured Video for WordPress – VideographyWP has a strong security track record. Known vulnerabilities have been patched promptly.
The "videographywp" plugin v1.0.20 demonstrates a mixed security posture. On the positive side, the static analysis reveals a clean attack surface with no direct entry points such as AJAX handlers, REST API routes, shortcodes, or cron events that lack authentication or permission checks. Furthermore, all SQL queries are properly prepared, indicating good database interaction practices, and there are no detected file operations or external HTTP requests, which mitigates certain attack vectors. However, a significant concern arises from the output escaping, where only 64% of outputs are properly escaped. This leaves a portion of user-generated or dynamically generated content potentially vulnerable to Cross-Site Scripting (XSS) attacks, a risk amplified by the plugin's history of a medium-severity XSS vulnerability. The taint analysis showing zero flows is encouraging, but it doesn't negate the existing risk from unescaped output and past vulnerabilities.
Key Concerns
- Moderate percentage of unescaped output
- Past medium severity XSS vulnerability
Featured Video for WordPress – VideographyWP Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Featured Video for WordPress – VideographyWP <= 1.0.18 - Authenticated (Contributor+) Stored Cross-Site Scripting
Featured Video for WordPress – VideographyWP Code Analysis
SQL Query Safety
Output Escaping
Featured Video for WordPress – VideographyWP Attack Surface
WordPress Hooks 5
Maintenance & Trust
Featured Video for WordPress – VideographyWP Maintenance & Trust
Maintenance Signals
Community Trust
Featured Video for WordPress – VideographyWP Alternatives
Simply Featured Video – Featured video support for WordPress
simply-featured-video
Simply Featured Video allows you to set a featured video from media library, YouTube, Vimeo, and more.
The Ultimate Video Player For WordPress – by Presto Player
presto-player
The Ultimate WordPress Video Player.
All-in-One Video Gallery
all-in-one-video-gallery
The ultimate video player & video gallery plugin for YouTubers, Video Bloggers, Course Creators, Podcasters, and anyone embedding videos on websites.
WP Video Popup – WordPress Video Lightbox for YouTube, Rumble & Vimeo
responsive-youtube-vimeo-popup
WP Video Popup lets you add a responsive YouTube, Rumble or Vimeo video lightbox to any page, post or custom post type of your website.
Automatic Featured Images from Videos
automatic-featured-images-from-videos
If a YouTube or Vimeo video embed exists near the start of a post, we'll automatically set the post's featured image to a thumbnail of the video.
Featured Video for WordPress – VideographyWP Developer Profile
3 plugins · 2K total installs
How We Detect Featured Video for WordPress – VideographyWP
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/videographywp/assets/css/videographywp.css/wp-content/plugins/videographywp/assets/js/videographywp.js/wp-content/plugins/videographywp/assets/js/videographywp.jsvideographywp/assets/css/videographywp.css?ver=videographywp/assets/js/videographywp.js?ver=HTML / DOM Fingerprints
cvwp-video-wrapper