VideoWhisper Site Manager Security & Risk Analysis

wordpress.org/plugins/videowhisper-site-manager

Manage WordPress posts and pages from ChatGPT (including mobile app) using your account (and subscription).

0 active installs v0.2.1 PHP 7.4+ WP 5.6+ Updated Mar 14, 2026
aichatgptgpt-actionsrest-apiwordpress-automation
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is VideoWhisper Site Manager Safe to Use in 2026?

Generally Safe

Score 100/100

VideoWhisper Site Manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 20d ago
Risk Assessment

The "videowhisper-site-manager" plugin v0.2.1 exhibits a generally good security posture based on the provided static analysis. The absence of any identified CVEs, critical or high severity taint flows, and a protected attack surface (no unprotected AJAX handlers, REST API routes, or shortcodes) are strong indicators of sound development practices. The plugin also demonstrates a reasonable use of security features with numerous nonce and capability checks, and a majority of its SQL queries utilizing prepared statements. However, a notable concern is the percentage of improperly escaped output (40%). This could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is not properly sanitized before being displayed to users. While the current version shows no known vulnerabilities, this output escaping issue represents a potential risk that should be addressed in future updates.

Key Concerns

  • Significant portion of output not properly escaped
Vulnerabilities
None known

VideoWhisper Site Manager Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

VideoWhisper Site Manager Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
4 prepared
Unescaped Output
144
212 escaped
Nonce Checks
5
Capability Checks
15
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

67% prepared6 total queries

Output Escaping

60% escaped356 total outputs
Attack Surface

VideoWhisper Site Manager Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actioninitincludes\class-plugin.php:91
actionrest_api_initincludes\class-plugin.php:92
actionadmin_menuincludes\class-plugin.php:93
actionadmin_enqueue_scriptsincludes\class-plugin.php:94
actionadmin_noticesincludes\class-plugin.php:95
actionadmin_post_vwsm_save_settingsincludes\class-plugin.php:96
actionadmin_post_vwsm_dismiss_onboarding_noticeincludes\class-plugin.php:97
actionadmin_post_vwsm_create_operator_userincludes\class-plugin.php:98
actionadmin_post_vwsm_create_application_passwordincludes\class-plugin.php:99
actionadmin_post_vwsm_remove_operator_userincludes\class-plugin.php:100
actionvwsm_daily_audit_cleanupincludes\class-plugin.php:101

Scheduled Events 2

vwsm_daily_audit_cleanup
vwsm_daily_audit_cleanup
Maintenance & Trust

VideoWhisper Site Manager Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 14, 2026
PHP min version7.4
Downloads88

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

VideoWhisper Site Manager Developer Profile

videowhisper

12 plugins · 1K total installs

74
trust score
Avg Security Score
93/100
Avg Patch Time
1072 days
View full developer profile
Detection Fingerprints

How We Detect VideoWhisper Site Manager

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/videowhisper-site-manager/assets/js/admin-onboarding.js
Script Paths
/wp-content/plugins/videowhisper-site-manager/assets/js/admin-onboarding.js
Version Parameters
videowhisper-site-manager/assets/js/admin-onboarding.js?ver=

HTML / DOM Fingerprints

JS Globals
vwsmOnboarding
FAQ

Frequently Asked Questions about VideoWhisper Site Manager