
Easy Video Widget Box Security & Risk Analysis
wordpress.org/plugins/widget-video-boxSimple plugin to add video into your widget box. Supports Youtube, Dailymotion, Vimeo and many other sites that provide embed code..
Is Easy Video Widget Box Safe to Use in 2026?
Generally Safe
Score 85/100Easy Video Widget Box has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'widget-video-box' plugin version 1.6 exhibits a mixed security posture. On one hand, the plugin demonstrates a commendable lack of known vulnerabilities in its history and appears to have a minimal attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events exposed without authorization. All SQL queries are also correctly using prepared statements.
However, significant concerns arise from the static code analysis. The presence of the `create_function` is a direct indicator of potential security risks, as this function is deprecated and can be a source of vulnerabilities if not handled with extreme care. More critically, 100% of the plugin's output is not properly escaped, which presents a high risk of Cross-Site Scripting (XSS) vulnerabilities. This means that any data processed by the plugin that is later displayed to users could potentially be manipulated by attackers to inject malicious scripts.
The absence of nonce checks and capability checks across all entry points, coupled with the lack of proper output escaping, suggests a significant oversight in secure coding practices. While there are no direct taint flows with unsanitized paths identified in this analysis, the combination of these factors creates a fertile ground for potential exploitation. The plugin's history of no recorded vulnerabilities might be due to its limited usage, obscurity, or perhaps previous versions having different, more secure implementations. However, the current version's code indicates a substantial security debt that needs to be addressed.
Key Concerns
- 0% of output properly escaped
- Use of deprecated and dangerous function: create_function
- Missing nonce checks on entry points
- Missing capability checks on entry points
Easy Video Widget Box Security Vulnerabilities
Easy Video Widget Box Code Analysis
Dangerous Functions Found
Output Escaping
Easy Video Widget Box Attack Surface
WordPress Hooks 1
Maintenance & Trust
Easy Video Widget Box Maintenance & Trust
Maintenance Signals
Community Trust
Easy Video Widget Box Alternatives
Wonder Video Embed
wonderplugin-video-embed
Embed MP4, Youtube, Vimeo, Wistia videos to the sidebar widget, WordPress posts and pages.
Aparat WordPress Video Feed Plugin
aparat-feed
Easily display the latest videos from any Aparat channel on your WordPress site with a lightweight, fast and responsive Aparat video WordPress plugin.
The Media Widget
the-media-widget
Display media in text widget easily, youtube video, vimeo video, instagram image, easy to use just paste link! fully responsive and custom height.
Floating Video Widget
floating-video-widget
Add a customizable floating video widget to any page or post using a simple shortcode.
Mirror App – Video Feed
mirror-app-video-feed
Display videos from YouTube on your WordPress website using a clean, customizable video feed. Embed videos from channels or playlists with a simple sh …
Easy Video Widget Box Developer Profile
3 plugins · 1K total installs
How We Detect Easy Video Widget Box
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/widget-video-box/video-box.phpHTML / DOM Fingerprints
video-box<!-- Begin Video.js --><!-- End Video.js -->video-jsvjs-default-skin<div class="video-box">