
ViewMedica 9 Security & Risk Analysis
wordpress.org/plugins/viewmedicaViewMedica 9 for WordPress Instantly embed your ViewMedica On-Demand in to your website
Is ViewMedica 9 Safe to Use in 2026?
Generally Safe
Score 90/100ViewMedica 9 has a strong security track record. Known vulnerabilities have been patched promptly.
The viewmedica plugin v1.4.21 presents a mixed security posture. On the positive side, the static analysis reveals good practices in several areas. All SQL queries are properly prepared, indicating a reduced risk of SQL injection. There are no identified dangerous functions or file operations, which are common vectors for attacks. Furthermore, the plugin demonstrates a commitment to input validation with a reasonable number of nonce and capability checks. The absence of critical or high-severity taint analysis findings is also a reassuring sign. However, concerns arise from the output escaping. With only 25% of outputs properly escaped, there is a significant risk of Cross-Site Scripting (XSS) vulnerabilities. This lack of robust output sanitization could allow attackers to inject malicious scripts through various plugin functionalities. The plugin's vulnerability history, despite having no currently unpatched CVEs, shows a past pattern of 3 medium-severity vulnerabilities, primarily related to XSS and CSRF. This suggests that while the developers have addressed past issues, the underlying code may still have weaknesses that can lead to similar vulnerabilities. The presence of external HTTP requests without further context also warrants caution, as compromised external resources could potentially impact the plugin's security. Overall, the plugin exhibits strengths in data handling and authentication mechanisms but requires immediate attention to its output escaping practices to mitigate significant XSS risks.
Key Concerns
- Low output escaping percentage (25%)
- Previous medium severity vulnerabilities (3)
- External HTTP requests without context
ViewMedica 9 Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
ViewMedica 9 <= 1.4.18 - Authenticated (Contributor+) Stored Cross-Site Scripting
ViewMedica Embed <= 1.4.15 - Cross-Site Request Forgery to SQL Injection
ViewMedica 9 <= 1.4.17 - Cross-Site Request Forgery to Reflected Cross-Site Scripting
ViewMedica 9 Release Timeline
ViewMedica 9 Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
ViewMedica 9 Attack Surface
Shortcodes 1
WordPress Hooks 11
Maintenance & Trust
ViewMedica 9 Maintenance & Trust
Maintenance Signals
Community Trust
ViewMedica 9 Alternatives
Feeds for TikTok (TikTok feed, video, and gallery plugin)
feeds-for-tiktok
The best way to display TikTok videos on your WordPress website. Display clean, customizable, and responsive TikTok feeds from your TikTok account.
Video Gallery – YouTube Playlist, Channel Gallery by YotuWP
yotuwp-easy-youtube-embed
Modern responsive YouTube video gallery helps your website getting noticed from visitors, increase the reach and stand out from the competitors.
Featured Video Plus
featured-video-plus
Add Featured Videos to your posts and pages. Works like magic with most themes which use Featured Images. Local Media, YouTube, Vimeo and many more.
SocialFeeds
socialfeeds
YouTube feeds for WordPress with simple Setup and Settings options.
Porn Videos Embed
porn-videos-embed
A very simple wordpress plugin for add shortcode embed videos from porn sites
ViewMedica 9 Developer Profile
1 plugin · 200 total installs
How We Detect ViewMedica 9
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/viewmedica/vm_event_listener.jshttps://ondemand.viewmedica.com/lib/vm.jsviewmedica/vm_event_listener.js?ver=viewmedica/vm_event_listener.js?ver=1.1.0HTML / DOM Fingerprints
<!-- ViewMedica Embed End -->vm_open<div id='vm'></div><div id=''></div>