WC Product Videos Security & Risk Analysis

wordpress.org/plugins/wc-product-videos

This plugin allows you to replace your WooCommerce product images with a YouTube video.

0 active installs v1.0.0 PHP + WP 3.0.1+ Updated Jun 30, 2019
productvideowoocommerceyoutube
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is WC Product Videos Safe to Use in 2026?

Generally Safe

Score 85/100

WC Product Videos has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The "wc-product-videos" plugin v1.0.0 exhibits a generally strong security posture based on the provided static analysis. There are no identified dangerous functions, SQL queries are all prepared, and file operations and external HTTP requests are absent. The majority of output is properly escaped, and the plugin has a clean vulnerability history with no recorded CVEs. This suggests a developer who is aware of and implementing many core security best practices.

However, the complete absence of nonces, capability checks, and any identified taint flows is notable. While this may indicate a lack of complex user interaction or data handling, it also means that the plugin has zero built-in protections against common WordPress attack vectors like Cross-Site Request Forgery (CSRF) or unauthorized actions if an attacker were able to inject malicious requests. The limited number of outputs and absence of other entry points also makes it difficult to fully assess the escaping of all potential data. Despite the lack of historical vulnerabilities and good coding practices observed, the missing authentication and authorization checks represent a potential area of weakness that could be exploited in specific scenarios.

In conclusion, the "wc-product-videos" plugin v1.0.0 appears to be a relatively secure option, demonstrating good development habits in several key areas and having no known vulnerabilities. The primary concern lies in the complete lack of any authentication or authorization checks on its limited entry points, which leaves it susceptible to certain types of attacks if those entry points were ever to become more complex or exposed. Further review of the plugin's functionality to understand the impact of these missing checks would be beneficial.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
  • Limited output escaping
Vulnerabilities
None known

WC Product Videos Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

WC Product Videos Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

80% escaped5 total outputs
Attack Surface

WC Product Videos Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actionplugins_loadedincludes\class-woocommerce-product-videos.php:142
actionadmin_enqueue_scriptsincludes\class-woocommerce-product-videos.php:157
actionadmin_enqueue_scriptsincludes\class-woocommerce-product-videos.php:158
actionadd_meta_boxesincludes\class-woocommerce-product-videos.php:159
actionsave_postincludes\class-woocommerce-product-videos.php:160
actionwp_enqueue_scriptsincludes\class-woocommerce-product-videos.php:174
actionwp_enqueue_scriptsincludes\class-woocommerce-product-videos.php:175
actionwoocommerce_after_single_product_summaryincludes\class-woocommerce-product-videos.php:177
filterwoocommerce_single_product_image_thumbnail_htmlincludes\class-woocommerce-product-videos.php:178
Maintenance & Trust

WC Product Videos Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedJun 30, 2019
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

WC Product Videos Developer Profile

Glen Scott

4 plugins · 920 total installs

80
trust score
Avg Security Score
80/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WC Product Videos

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wc-product-videos/css/woocommerce-product-videos-admin.css/wp-content/plugins/wc-product-videos/js/woocommerce-product-videos-admin.js
Script Paths
/wp-content/plugins/wc-product-videos/js/woocommerce-product-videos-admin.js
Version Parameters
woocommerce-product-videos-admin.css?ver=woocommerce-product-videos-admin.js?ver=

HTML / DOM Fingerprints

Data Attributes
name="youtube_url"id="youtube_url"name="video_position"id="video_position"
FAQ

Frequently Asked Questions about WC Product Videos