
Aparat for WordPress Security & Risk Analysis
wordpress.org/plugins/wp-aparatDisplaying Aparat videos on website content, along with a widget for showing a list of channel videos.
Is Aparat for WordPress Safe to Use in 2026?
Generally Safe
Score 92/100Aparat for WordPress has a strong security track record. Known vulnerabilities have been patched promptly.
The plugin "wp-aparat" v2.2.4 exhibits a generally good security posture with some notable strengths, particularly in its handling of SQL queries and its limited attack surface. The absence of dangerous functions, file operations, and a lack of critical or high-severity taint flows are positive indicators. The plugin also demonstrates some use of capability checks. However, a significant concern arises from the "Output escaping" metric, where only 42% of outputs are properly escaped. This leaves a substantial portion of user-generated or dynamic content potentially vulnerable to Cross-Site Scripting (XSS) attacks, especially when combined with the past XSS vulnerability recorded in its history.
The vulnerability history reveals a past medium-severity XSS vulnerability, which, although currently patched, highlights a recurring pattern of input sanitization weaknesses. The static analysis shows no nonce checks, which is a concern for any plugin with entry points, even if they are currently protected by capability checks or not directly exposed via AJAX/REST API. While the attack surface is small and currently appears to be protected, the low percentage of properly escaped output is the most significant area of immediate risk and warrants careful attention.
Key Concerns
- Low percentage of properly escaped outputs
- Past medium severity XSS vulnerability
- No nonce checks found
Aparat for WordPress Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Aparat for WordPress <= 2.2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
Aparat for WordPress Code Analysis
Bundled Libraries
Output Escaping
Aparat for WordPress Attack Surface
Shortcodes 1
WordPress Hooks 13
Maintenance & Trust
Aparat for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
Aparat for WordPress Alternatives
Namasha By Mdesign
namasha-by-mdesign
نمایش حرفه ای ویدیو های پلتفرم نماشا + آپارات در وردپرس (+ویجت المنتور و گوتنبرگ)
Aparat WordPress Video Feed Plugin
aparat-feed
Easily display the latest videos from any Aparat channel on your WordPress site with a lightweight, fast and responsive Aparat video WordPress plugin.
Aparat Embed
aparat-embed
Display Aparat videos and channels in WordPress.
WP Video Lightbox
wp-video-lightbox
Very easy to use WordPress lightbox plugin to display YouTube and Vimeo videos in an elegant lightbox overlay.
Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick …
advanced-responsive-video-embedder
Level up your basic video embeds! Advanced features, privacy. Use URLs, Shortcodes or Blocks to customize videos to your needs.
Aparat for WordPress Developer Profile
1 plugin · 4K total installs
How We Detect Aparat for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-aparat/assets/css/wp-aparat.min.css/wp-content/plugins/wp-aparat/assets/js/wp-aparat.min.js/wp-content/plugins/wp-aparat/assets/js/tinymce-editor-plugin.min.js/wp-content/plugins/wp-aparat/assets/js/wp-aparat-block.js/wp-content/plugins/wp-aparat/assets/css/wp-aparat-block.min.css/wp-content/plugins/wp-aparat/assets/js/wp-aparat.min.js/wp-content/plugins/wp-aparat/assets/js/tinymce-editor-plugin.min.js/wp-content/plugins/wp-aparat/assets/js/wp-aparat-block.jswp-aparat/assets/css/wp-aparat.min.css?ver=wp-aparat/assets/js/wp-aparat.min.js?ver=wp-aparat/assets/js/tinymce-editor-plugin.min.js?ver=wp-aparat/assets/js/wp-aparat-block.js?ver=wp-aparat/assets/css/wp-aparat-block.min.css?ver=HTML / DOM Fingerprints
aparat-frameaparat-full-frameaparat-half-frameaparat_plugin_urlaparat_video_addaparat_video_idaparat_video_id_insertaparat_video_id_descaparat_video_width+4 more<iframe src='https://www.aparat.com/video/video/embed/videohash/' width='' height='' allowfullscreen='true' class='aparat-frame'></iframe>