WP Brightcove Portal Security & Risk Analysis

wordpress.org/plugins/wp-brightcove-portal

Brightcove Portal will help you to add your brightcove videos to wordress from different brightcove accounts. Also you will be able to edit/delete vid …

10 active installs v1.1 PHP + WP 3.4+ Updated Jan 7, 2014
brightcovebrightcove-cloudcloudmediavideo
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP Brightcove Portal Safe to Use in 2026?

Generally Safe

Score 85/100

WP Brightcove Portal has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12yr ago
Risk Assessment

The wp-brightcove-portal v1.1 plugin exhibits a mixed security posture. While it benefits from a small attack surface with no directly identified vulnerabilities in its history and a relatively low number of SQL queries, significant concerns arise from the static analysis. The complete lack of output escaping is a critical weakness, potentially exposing users to cross-site scripting (XSS) vulnerabilities. Furthermore, the taint analysis reveals three high-severity flows with unsanitized paths, indicating potential for unauthorized data access or manipulation, despite the absence of critical severity issues. The absence of nonce checks and capability checks on any entry points, including the single shortcode, is a substantial oversight, further exacerbating the risk of unauthorized actions. The plugin's vulnerability history is clean, which is positive, but it does not mitigate the immediate risks identified in the current codebase. Overall, the plugin's strengths in avoiding known historical vulnerabilities are overshadowed by critical code-level security flaws that require immediate attention.

Key Concerns

  • 0% properly escaped output
  • 3 high severity unsanitized paths
  • 0 nonce checks on entry points
  • 0 capability checks on entry points
Vulnerabilities
None known

WP Brightcove Portal Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

WP Brightcove Portal Code Analysis

Dangerous Functions
0
Raw SQL Queries
7
18 prepared
Unescaped Output
58
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

SQL Query Safety

72% prepared25 total queries

Output Escaping

0% escaped58 total outputs
Data Flows
4 unsanitized

Data Flow Analysis

4 flows4 with unsanitized paths
<functions> (resources\functions.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

WP Brightcove Portal Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[bcPortal] wp-brightcove-portal.php:325
WordPress Hooks 8
actionadmin_menuwp-brightcove-portal.php:15
actionplugins_loadedwp-brightcove-portal.php:132
actioninitwp-brightcove-portal.php:143
actionwp_logoutwp-brightcove-portal.php:144
actionwp_loginwp-brightcove-portal.php:145
actionadd_meta_boxeswp-brightcove-portal.php:159
actioninitwp-brightcove-portal.php:328
actioninitwp-brightcove-portal.php:337
Maintenance & Trust

WP Brightcove Portal Maintenance & Trust

Maintenance Signals

WordPress version tested3.5.2
Last updatedJan 7, 2014
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

WP Brightcove Portal Developer Profile

pl4g4

2 plugins · 110 total installs

76
trust score
Avg Security Score
74/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP Brightcove Portal

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-brightcove-portal/img/menuIcon.png/wp-content/plugins/wp-brightcove-portal/resources/functions.php
Script Paths
http://admin.brightcove.com/js/BrightcoveExperiences.jshttp://admin.brightcove.com/js/APIModules_all.js

HTML / DOM Fingerprints

CSS Classes
BrightcoveExperience
HTML Comments
<!-- Start of Brightcove Player -->By use of this code snippet, I agree to the Brightcove Publisher T and C found at http://corp.brightcove.com/legal/terms_publisher.cfm.
Data Attributes
data-bc-portal
JS Globals
wpBrightcovePortalMenuwpBrightcovePortalsettingswpBrightcovePortalPlayerscreateBCPortalPlugincreateBCPortalPlugin_update_db_checkmyStartSession+8 more
Shortcode Output
[bcPortal
FAQ

Frequently Asked Questions about WP Brightcove Portal