
Wonder Video Embed Security & Risk Analysis
wordpress.org/plugins/wonderplugin-video-embedEmbed MP4, Youtube, Vimeo, Wistia videos to the sidebar widget, WordPress posts and pages.
Is Wonder Video Embed Safe to Use in 2026?
Generally Safe
Score 91/100Wonder Video Embed has a strong security track record. Known vulnerabilities have been patched promptly.
The wonderplugin-video-embed v2.4 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by using prepared statements for all SQL queries, performing nonce and capability checks on its entry points, and having no observed external HTTP requests or file operations. The limited attack surface, with only one shortcode and no unprotected AJAX handlers or REST API routes, further contributes to its security. However, the presence of the `unserialize` function as a dangerous function signal is a significant concern, as it can lead to Remote Code Execution if not handled with extreme caution and robust input validation.
The static analysis also reveals that a notable percentage of output is not properly escaped, which poses a risk of Cross-Site Scripting (XSS) vulnerabilities. While the taint analysis shows no flows with unsanitized paths and no critical or high severity issues, the unescaped output is a precursor to such problems. The vulnerability history indicates a pattern of medium-severity XSS vulnerabilities in the past, with the last one being relatively recent. Although there are currently no unpatched CVEs, this history suggests a recurring weakness in input sanitization or output encoding within the plugin.
In conclusion, while the plugin has a controlled attack surface and employs some fundamental security measures like prepared statements and permission checks, the identified dangerous function (`unserialize`) and the high percentage of unescaped output, coupled with a history of XSS vulnerabilities, present notable risks. The developers should prioritize addressing these areas to improve the plugin's overall security and prevent future exploits.
Key Concerns
- Dangerous function unserialize detected
- 43% of outputs not properly escaped
- History of medium severity XSS vulnerabilities
Wonder Video Embed Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Wonder Video Embed <= 2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Wonder Video Embed <= 1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting
Wonder Video Embed Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
Wonder Video Embed Attack Surface
Shortcodes 1
WordPress Hooks 8
Maintenance & Trust
Wonder Video Embed Maintenance & Trust
Maintenance Signals
Community Trust
Wonder Video Embed Alternatives
WP Video Lightbox
wp-video-lightbox
Very easy to use WordPress lightbox plugin to display YouTube and Vimeo videos in an elegant lightbox overlay.
YT Player – Embed and Customize Video Players
yt-player
A modern, accessible, fully customizable & user-friendly YouTube Video Player for WordPress.
HLS Player
hls-player
HLS Player is a lightweight HTTP Live Streaming player for WordPress, using video.js for easy embedding HLS videos into posts and pages.
Faster YouTube Embed
faster-youtube-embed
Faster YouTube Embed enables you to insert YouTube videos to any page and post quickly and efficiently & you’ll have no hassle of slow YouTube vid …
click-to-vote.me
click-to-vote-me
Very easy to use WordPress plugin to display click-to-vote.me polls.
Wonder Video Embed Developer Profile
6 plugins · 26K total installs
How We Detect Wonder Video Embed
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wonderplugin-video-embed/app/wonderplugin-videoembed-creator.js/wp-content/plugins/wonderplugin-video-embed/app/wonderplugin-videoembed-creator.css/wp-content/plugins/wonderplugin-video-embed/engine/wonderpluginvideoembed.js/wp-content/plugins/wonderplugin-video-embed/wonderpluginvideoembed.css/wp-content/plugins/wonderplugin-video-embed/app/wonderplugin-videoembed-mce.jswonderplugin-video-embed/engine/wonderpluginvideoembed.js?ver=wonderplugin-video-embed/app/wonderplugin-videoembed-creator.js?ver=HTML / DOM Fingerprints
wonderplugin-video-embedwpve-video-embed-wrapwpve-main-wrapdata-wonderplugin-video-embeddata-optionsWONDERPLUGIN_VIDEO_MCE_EDITOR[wonderplugin_video