
WP Video Enhanced Security & Risk Analysis
wordpress.org/plugins/wp-video-enhancedExtending Native WordPress Player with New Features. Logo & Branding, GDPR Consent, HLS, M(PEG)-DASH, Live Streaming, Configure Initial Volume and …
Is WP Video Enhanced Safe to Use in 2026?
Generally Safe
Score 85/100WP Video Enhanced has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-video-enhanced plugin v1.3.0 exhibits several concerning security practices despite having no recorded historical vulnerabilities. The primary areas of risk stem from its "attack surface" analysis, which reveals two AJAX handlers with no authentication checks. This means any unauthenticated user could potentially interact with these handlers, leading to an open door for malicious activity if the functionality they trigger is sensitive.
The "code signals" section further amplifies these concerns. The presence of dangerous functions like `create_function` and `unserialize` are significant red flags. `create_function` is deprecated and can lead to code injection if not handled with extreme care, while `unserialize` is notoriously prone to object injection vulnerabilities when processing untrusted input. The low percentage of properly escaped output (55%) indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the site.
While the plugin demonstrates good practices in using prepared statements for SQL queries and has no external HTTP requests, these strengths are overshadowed by the critical weaknesses in authentication, input sanitization, and output escaping. The lack of any recorded CVEs in its history might suggest either infrequent targeting or a fortunate lack of exploitation. However, given the identified code flaws, this plugin should be treated with caution and ideally updated or replaced with a more secure alternative.
Key Concerns
- Unprotected AJAX handlers
- Use of dangerous function: unserialize
- Use of dangerous function: create_function
- Low percentage of properly escaped output
- Missing nonce checks on AJAX
- Missing capability checks
WP Video Enhanced Security Vulnerabilities
WP Video Enhanced Release Timeline
WP Video Enhanced Code Analysis
Dangerous Functions Found
Output Escaping
WP Video Enhanced Attack Surface
AJAX Handlers 2
WordPress Hooks 14
Maintenance & Trust
WP Video Enhanced Maintenance & Trust
Maintenance Signals
Community Trust
WP Video Enhanced Alternatives
Khattam – Image Watermark
khattam
Add professional watermarks to your WordPress images with customizable position, size, and opacity settings.
Castio.live – Live Streaming Plugin for WordPress (HLS) + Real-Time Chat
castio-live
Live streaming plugin for WordPress with HLS, real-time chat, PayPal & Stripe paywall, and Gutenberg blocks. No OBS, no RTMP.
MediaHaven – Video Gallery & HLS Player With YouTube & TikTok
mediahaven-lite
🚀 Performance & security-focused HLS & self-hosted video player. Powerful video gallery with YouTube & TikTok feeds, AJAX loading & setup wizard.
ZW Player Video Embed
zw-player-video-embed
Professional HTML5 video player supporting HLS, DASH, FLV, MP4, local file with screenshot, recording, PIP and live streaming features.
Better Search Replace
better-search-replace
A simple plugin to update URLs or other text in a database.
WP Video Enhanced Developer Profile
3 plugins · 29K total installs
How We Detect WP Video Enhanced
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-video-enhanced/admin/assets/js/wpve-admin.js/wp-content/plugins/wp-video-enhanced/assets/css/wpve-public.css/wp-content/plugins/wp-video-enhanced/assets/js/wpve-public.jswp-color-pickerwp-video-enhanced/admin/assets/js/wpve-admin.jswpve-public.jswp-video-enhanced/admin/assets/js/wpve-admin.js?ver=wp-video-enhanced/assets/css/wpve-public.css?ver=wp-video-enhanced/assets/js/wpve-public.js?ver=HTML / DOM Fingerprints
wpve-video-wrapperdata-wpve-videowpve_vars[video[wp_video_enhanced