
Vimeo Everywhere Security & Risk Analysis
wordpress.org/plugins/vimeo-everywhereDisplay your public Vimeo videos on your WordPress website via shortcode, widget, or dashboard menu. Perfect for making a custom training library
Is Vimeo Everywhere Safe to Use in 2026?
Generally Safe
Score 85/100Vimeo Everywhere has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "vimeo-everywhere" plugin, version 2.1, presents a mixed security posture. On the positive side, the plugin has no known historical vulnerabilities (CVEs) and demonstrates a clean record with no unpatched issues. The static analysis reveals a limited attack surface, with only one shortcode entry point and no AJAX handlers, REST API routes, or cron events. Furthermore, all identified SQL queries utilize prepared statements, which is a strong indicator of secure database interaction. However, there are significant concerns raised by the static analysis. The presence of 14 instances of the dangerous `unserialize` function is a major red flag, as it can lead to remote code execution if used with untrusted data. The extremely low percentage of properly escaped output (5%) suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data is likely being rendered directly without adequate sanitization. The absence of nonce checks and capability checks across the plugin's codebase is also concerning, as it indicates a lack of protection against common WordPress attacks like Cross-Site Request Forgery (CSRF) and privilege escalation, especially in conjunction with the `unserialize` function.
Key Concerns
- Use of unserialize function
- Low output escaping percentage
- Missing nonce checks
- Missing capability checks
Vimeo Everywhere Security Vulnerabilities
Vimeo Everywhere Code Analysis
Dangerous Functions Found
Output Escaping
Vimeo Everywhere Attack Surface
Shortcodes 1
WordPress Hooks 11
Maintenance & Trust
Vimeo Everywhere Maintenance & Trust
Maintenance Signals
Community Trust
Vimeo Everywhere Alternatives
Easy Support Videos – Embed videos in the admin
easy-support-videos
Easy Support Videos for embedding helpful tutorials, training videos, and screencasts in the Admin dashboard. Works with YouTube, Vimeo, Wistia, Video …
Responsive videos – Fitvids
responsive-videos-fitvids
Make your Embedded videos responsive on mobile devices with jQuery FitVids plugin
WP Theater
wp-theater
Shortcodes for YouTube and Vimeo. Includes embeds, "Theater" embed, thumbed previews, playlist, channel, user uploads and groups.
WP Videos
video-sync-for-vimeo
WP Videos creates Video post types that you can easily add Vimeo, YouTube, WordPress, Shortcode or custom embed (third party) HTML and JS videos to.
Advanced Videos Feed for Elementor
advanced-videos-feed-for-elementor
Display beautiful video feeds from various sources using Elementor widgets.
Vimeo Everywhere Developer Profile
4 plugins · 280 total installs
How We Detect Vimeo Everywhere
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/vimeo-everywhere/includes/adminstyle.css/wp-content/plugins/vimeo-everywhere/includes/style.cssHTML / DOM Fingerprints
pyd_leftdata-albumiddata-videoiddata-channeliddata-albumtitledata-vidtitledata-iconsize+3 moreadd_my_script[pydvimeovideos]