
wordpress-flowplayer Security & Risk Analysis
wordpress.org/plugins/wordpress-flowplayerAdds a flow tag to your new post and new page section, that allows you to easily add videos to your posts.
Is wordpress-flowplayer Safe to Use in 2026?
Generally Safe
Score 85/100wordpress-flowplayer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wordpress-flowplayer plugin v0.3 exhibits a mixed security posture. On the positive side, there are no known vulnerabilities (CVEs) recorded, and the code shows good practices such as 100% of SQL queries using prepared statements and no file operations or external HTTP requests. Furthermore, the attack surface is minimal, with zero identified AJAX handlers, REST API routes, shortcodes, or cron events that are accessible to external users.
However, there are significant concerns related to output escaping and taint analysis. A concerning 17% of the identified output points are not properly escaped, posing a risk of Cross-Site Scripting (XSS) vulnerabilities. Additionally, the taint analysis revealed one flow with an unsanitized path, which could potentially lead to path traversal vulnerabilities if not handled carefully. The absence of any nonce checks on potential entry points, while currently having no entry points, suggests a lack of defense-in-depth for future development. The presence of a bundled library (TinyMCE) also introduces a potential risk if it's outdated and has known vulnerabilities.
While the plugin's lack of known CVEs is a strong indicator of a relatively safe history, the static analysis reveals specific weaknesses that could be exploited. The limited attack surface is a significant strength, but the unescaped output and the single unsanitized path flow are areas requiring immediate attention. The plugin's strengths lie in its lack of historical vulnerabilities and secure database interaction, but its weaknesses lie in potential client-side vulnerabilities due to insufficient output escaping and a potential path-related issue.
Key Concerns
- Unescaped output detected
- Flow with unsanitized path detected
- Bundled library (TinyMCE) may be outdated
- No nonce checks implemented
wordpress-flowplayer Security Vulnerabilities
wordpress-flowplayer Release Timeline
wordpress-flowplayer Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
wordpress-flowplayer Attack Surface
WordPress Hooks 8
Maintenance & Trust
wordpress-flowplayer Maintenance & Trust
Maintenance Signals
Community Trust
wordpress-flowplayer Alternatives
WP-SWFObject
wp-swfobject
Insert Flash Movies into WordPress.
Stream Video Player
stream-video-player
Stream Video Player for WordPress its one stop solution for high quality video publishing for web or iOS.
SWFPut – SWFlash Put
swfput
SWFPut provides video players for posts and pages and widget areas, as both HTML5 and flash video.
MK Auto Youtube Player
mk-auto-youtube-player
MK Auto Youtube Player will help you increase your sales conversion up to 50%.
MK Smart Player
mk-smart-player
MK Smart Player will allow you to play any video from the web or from Youtube.
wordpress-flowplayer Developer Profile
1 plugin · 10 total installs
How We Detect wordpress-flowplayer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wordpress-flowplayer/flowplayer-3.0.0.min.js/wp-content/plugins/wordpress-flowplayer/flowplayer-3.0.0.swf/wp-content/plugins/wordpress-flowplayer/flowplayer-3.0.0.min.jsHTML / DOM Fingerprints
flowPlayer<!-- Begin wordpress-flowplayer --><!-- End wordpress-flowplayer -->id="postnum-%POSTID%"pluginspage="http://www.adobe.com/go/getflashplayer"$f<a class="player plain" id="postnum-%POSTID%"><embed src="%PLAYER%" allowfullscreen="true" allowscriptaccess="always" quality="high" type="application/x-shockwave-flash" pluginspage="http://www.adobe.com/go/getflashplayer" id="postnum-%POSTID%" bgcolor="#000000" name="postnum-%POSTID%" flashvars="config={"clip":{"url":"%HREF%","autoPlay":false},"playerId":"postnum-%POSTID%","playlist":[{"url":"%HREF%","autoPlay":false}]}" width="%WIDTH%px" height="%HEIGHT%px"><a/>