Vimeography: Vimeo Video Gallery WordPress Plugin Security & Risk Analysis

wordpress.org/plugins/vimeography

The easiest way to create beautiful Vimeo video galleries on your WordPress site.

6K active installs v2.4.6 PHP 5.3+ WP 4.7+ Updated Apr 23, 2025
galleryvideovideo-galleryvimeovimeo-gallery
89
A · Safe
CVEs total3
Unpatched0
Last CVEDec 11, 2024
Safety Verdict

Is Vimeography: Vimeo Video Gallery WordPress Plugin Safe to Use in 2026?

Generally Safe

Score 89/100

Vimeography: Vimeo Video Gallery WordPress Plugin has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

3 known CVEsLast CVE: Dec 11, 2024Updated 1yr ago
Risk Assessment

The static analysis of Vimeography v2.4.6 reveals an exceptionally clean code base with no identified dangerous functions, file operations, external HTTP requests, or taint flows indicating potential vulnerabilities. The plugin also demonstrates good practices by using prepared statements for all SQL queries and properly escaping all output, contributing to a strong defense against common web attacks. The absence of any attack surface like AJAX handlers, REST API routes, shortcodes, or cron events further limits the plugin's exposure to potential exploitation. This suggests a robust development effort in securing this specific version.

However, the vulnerability history presents a significant concern. With a total of three known CVEs, including one high and two medium severity vulnerabilities, the plugin has a track record of security weaknesses. Although none are currently unpatched, the types of past vulnerabilities (Exposure of Sensitive Information, CSRF, Deserialization) are serious and could indicate underlying architectural issues or a history of less stringent security reviews. The most recent vulnerability was in December 2024, suggesting ongoing security challenges. While this specific version appears to be well-secured in its static analysis, the historical context warrants a cautious approach.

In conclusion, Vimeography v2.4.6 showcases excellent static code security practices, with no immediate code-level vulnerabilities detected. The plugin is well-hardened against typical web exploits at the code level. Nevertheless, its past vulnerability history, particularly concerning sensitive information exposure and deserialization, should not be overlooked. Users should remain vigilant and ensure they are always running the latest available version of the plugin, even if this specific version appears secure in static analysis, to benefit from any future patches addressing historical patterns.

Key Concerns

  • History of high severity vulnerabilities
  • History of medium severity vulnerabilities (2)
  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
3 published

Vimeography: Vimeo Video Gallery WordPress Plugin Security Vulnerabilities

CVEs by Year

3 CVEs in 2024
2024
Patched Has unpatched

Severity Breakdown

High
1
Medium
2

3 total CVEs

CVE-2024-54366medium · 5.3Exposure of Sensitive Information to an Unauthorized Actor

Vimeography <= 2.4.4 - Sensitive Information Exposure

Dec 11, 2024 Patched in 2.4.5 (9d)
CVE-2024-35770medium · 4.3Cross-Site Request Forgery (CSRF)

Vimeography: Vimeo Video Gallery WordPress Plugin <= 2.4.1 - Cross-Site Request Forgery

Jun 18, 2024 Patched in 2.4.2 (9d)
CVE-2024-0825high · 8.8Deserialization of Untrusted Data

Vimeography: Vimeo Video Gallery WordPress Plugin <= 2.3.2 - Authenticated (Contributor+) PHP Object Injection

Mar 4, 2024 Patched in 2.3.3 (148d)
Code Analysis
Analyzed Mar 16, 2026

Vimeography: Vimeo Video Gallery WordPress Plugin Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
0
3 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

100% escaped3 total outputs
Attack Surface

Vimeography: Vimeo Video Gallery WordPress Plugin Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionplugins_loadedvimeography-bugsauce\vimeography-bugsauce.php:27
actionplugins_loadedvimeography-harvestone\vimeography-harvestone.php:30
Maintenance & Trust

Vimeography: Vimeo Video Gallery WordPress Plugin Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedApr 23, 2025
PHP min version5.3
Downloads348K

Community Trust

Rating90/100
Number of ratings122
Active installs6K
Developer Profile

Vimeography: Vimeo Video Gallery WordPress Plugin Developer Profile

videogallery

1 plugin · 6K total installs

80
trust score
Avg Security Score
89/100
Avg Patch Time
55 days
View full developer profile
Detection Fingerprints

How We Detect Vimeography: Vimeo Video Gallery WordPress Plugin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/vimeography/lib/shared/assets/css/vimeography.css/wp-content/plugins/vimeography/lib/shared/assets/js/vimeography.js
Script Paths
/wp-content/plugins/vimeography/lib/shared/assets/js/vimeography.js
Version Parameters
vimeography/style.css?ver=vimeography.js?ver=

HTML / DOM Fingerprints

CSS Classes
vimeography-galleryvimeography-player-container
Data Attributes
data-vimeography-iddata-vimeography-settings
JS Globals
window.Vimeographyvar VimeographyPlayer
REST Endpoints
/wp-json/vimeography/v1/galleries/wp-json/vimeography/v1/themes
Shortcode Output
[vimeography]
FAQ

Frequently Asked Questions about Vimeography: Vimeo Video Gallery WordPress Plugin