Widgets for Vimeo Feed Security & Risk Analysis

wordpress.org/plugins/widgets-for-vimeo-feed

Vimeo Feed Widgets. Display your Vimeo feed on your website to increase engagement, sales and SEO.

0 active installs v1.7.9 PHP 7.0+ WP 6.2+ Updated Unknown
feedgalleryvideovimeowidget
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Widgets for Vimeo Feed Safe to Use in 2026?

Generally Safe

Score 100/100

Widgets for Vimeo Feed has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "widgets-for-vimeo-feed" plugin, version 1.7.9, exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of known CVEs and a clean vulnerability history suggest a commitment to security and a lack of past exploitable issues. Furthermore, the static analysis reveals no dangerous functions, all SQL queries use prepared statements, and all output is properly escaped. The presence of nonce and capability checks also indicates an effort to secure entry points. However, there are potential areas of concern. The taint analysis identified two flows with unsanitized paths, which, despite not being classified as critical or high severity in this specific analysis, represent a potential risk. While the attack surface is reported as zero, this could be an artifact of the analysis or the plugin's functionality. The plugin does make six external HTTP requests, which, depending on the nature of these requests and the data handled, could introduce risks if not properly validated or if the external service is compromised. In conclusion, the plugin demonstrates good security practices in core areas like SQL and output handling, but the unsanitized paths in taint analysis and the nature of external HTTP requests warrant careful consideration for a complete risk assessment.

Key Concerns

  • Flows with unsanitized paths found in taint analysis
  • External HTTP requests without apparent input validation context
Vulnerabilities
None known

Widgets for Vimeo Feed Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Widgets for Vimeo Feed Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
458 escaped
Nonce Checks
15
Capability Checks
4
File Operations
0
External Requests
6
Bundled Libraries
0

Output Escaping

100% escaped460 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

5 flows2 with unsanitized paths
<admin> (include\admin.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Widgets for Vimeo Feed Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 27
filterrocket_minify_excluded_external_jsinclude\cache-plugin-filters.php:13
filterrocket_exclude_jsinclude\cache-plugin-filters.php:14
filterrocket_delay_js_exclusionsinclude\cache-plugin-filters.php:15
filterlitespeed_optimize_js_excludesinclude\cache-plugin-filters.php:16
filtersgo_javascript_combine_excluded_external_pathsinclude\cache-plugin-filters.php:17
filtersgo_css_combine_excludeinclude\cache-plugin-filters.php:18
filterrocket_rucss_safelistinclude\cache-plugin-filters.php:58
filterscript_loader_taginclude\cache-plugin-filters.php:63
filterstyle_loader_taginclude\cache-plugin-filters.php:78
actionwp_footertrustindex-feed-plugin.class.php:4813
actionadmin_footertrustindex-feed-plugin.class.php:4814
filterfilesystem_methodtrustindex-feed-plugin.class.php:4898
actionadmin_noticestrustindex-feed-plugin.class.php:4923
actionplugins_loadedwidgets-for-vimeo-feed.php:34
actionadmin_menuwidgets-for-vimeo-feed.php:35
filterplugin_action_linkswidgets-for-vimeo-feed.php:36
filterplugin_row_metawidgets-for-vimeo-feed.php:37
actioninitwidgets-for-vimeo-feed.php:38
actionadmin_enqueue_scriptswidgets-for-vimeo-feed.php:39
actioninitwidgets-for-vimeo-feed.php:41
actioninitwidgets-for-vimeo-feed.php:57
filterscript_loader_tagwidgets-for-vimeo-feed.php:58
actionrest_api_initwidgets-for-vimeo-feed.php:64
actionadmin_noticeswidgets-for-vimeo-feed.php:105
actionelementor/widgets/widgets_registeredwidgets-for-vimeo-feed.php:147
actionelementor/elements/categories_registeredwidgets-for-vimeo-feed.php:151
actionwp_enqueue_scriptswidgets-for-vimeo-feed.php:160
Maintenance & Trust

Widgets for Vimeo Feed Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedUnknown
PHP min version7.0
Downloads491

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Widgets for Vimeo Feed Developer Profile

Trustindex

32 plugins · 976K total installs

87
trust score
Avg Security Score
98/100
Avg Patch Time
78 days
View full developer profile
Detection Fingerprints

How We Detect Widgets for Vimeo Feed

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/widgets-for-vimeo-feed/assets/css/frontend-notifictions.css/wp-content/plugins/widgets-for-vimeo-feed/assets/js/frontend-notifictions.js
Version Parameters
widgets-for-vimeo-feed/style.css?ver=widgets-for-vimeo-feed/admin.css?ver=widgets-for-vimeo-feed/admin.js?ver=widgets-for-vimeo-feed/trustindex-feed-plugin.class.js?ver=widgets-for-vimeo-feed/trustindex-feed-plugin.class.css?ver=widgets-for-vimeo-feed/assets/js/frontend-notifictions.js?ver=widgets-for-vimeo-feed/assets/css/frontend-notifictions.css?ver=

HTML / DOM Fingerprints

CSS Classes
trustindex-star-rowtrustindex-notice-dismisstrustindex-notification-rowti-close-notificationti-remind-laterti-hide-notificationti-button-primary
Data Attributes
data-close-urldata-redirect-url
JS Globals
TRUSTINDEX_Feed_Vimeo
REST Endpoints
/wp-json/widgets-for-vimeo-feed/v1/get-token/wp-json/widgets-for-vimeo-feed/v1/troubleshooting/wp-json/widgets-for-vimeo-feed/v1/refresh-data
FAQ

Frequently Asked Questions about Widgets for Vimeo Feed