
mb.YTPlayer for background videos Security & Risk Analysis
wordpress.org/plugins/wpmbytplayerPlay any Youtube video as background of your page or as custom player inside an element of the page.
Is mb.YTPlayer for background videos Safe to Use in 2026?
Use With Caution
Score 64/100mb.YTPlayer for background videos has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "wpmbytplayer" v3.3.8 plugin exhibits a mixed security posture. While it demonstrates good practices by exclusively using prepared statements for SQL queries and avoiding dangerous functions, several critical vulnerabilities are present. The plugin has a significant attack surface, with 3 total entry points, 2 of which are entirely unprotected (lacking authentication checks). This directly correlates with its vulnerability history, which includes a currently unpatched medium severity CVE, and a common vulnerability type of "Missing Authorization".
The taint analysis reveals that all analyzed flows involve unsanitized paths, although no critical or high severity issues were found in this specific scan. However, the lack of capability checks and nonce checks on AJAX handlers, combined with a low percentage (27%) of properly escaped output, indicate a strong potential for cross-site scripting (XSS) and other injection vulnerabilities, especially when combined with the unsanitized paths found in taint analysis.
Overall, while the plugin avoids some common pitfalls like raw SQL, the prevalence of unprotected entry points and the history of authorization issues, coupled with weak output escaping and unsanitized paths, present a substantial risk. The unpatched CVE is a particularly concerning indicator of ongoing security neglect. Users should be highly cautious and consider alternative solutions until these issues are addressed.
Key Concerns
- Unpatched CVE found
- 2 AJAX handlers without auth checks
- 0 Nonce checks on AJAX handlers
- 0 Capability checks
- Low output escaping (27%)
- 4 Taint flows with unsanitized paths
mb.YTPlayer for background videos Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
mb.YTPlayer <= 3.3.8 - Missing Authorization
mb.YTPlayer for background videos Code Analysis
Output Escaping
Data Flow Analysis
mb.YTPlayer for background videos Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 14
Maintenance & Trust
mb.YTPlayer for background videos Maintenance & Trust
Maintenance Signals
Community Trust
mb.YTPlayer for background videos Alternatives
Lean Video and Audio Player
lean-video-and-audio-player
Simple shortcode-based video and audio player supporting HTML5, YouTube, Vimeo and MP3 files with clean, modern interface.
Simple Video Post
simple-video-post
A simple video post plugin that support YouTube/Vimeo/Facebook/Dailymotion like video sharing website. No coding required.
All-in-One Video Gallery
all-in-one-video-gallery
The ultimate video player & video gallery plugin for YouTubers, Video Bloggers, Course Creators, Podcasters, and anyone embedding videos on websites.
FV Flowplayer Video Player
fv-wordpress-flowplayer
WordPress's most reliable, easy to use and feature-rich video player. Supports responsive design, HTML5, playlists, ads, stats, Vimeo and YouTube.
HTML5 Video Player – Embed and Play Videos in Custom Player
html5-video-player
HTML5 Video Player Plugin lets you embed responsive videos in WordPress. It’s easy to use, fast, and supports MP4, WebM, OGG, FLV, Youtube and Vimeo.
mb.YTPlayer for background videos Developer Profile
2 plugins · 5K total installs
How We Detect mb.YTPlayer for background videos
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wpmbytplayer/js/jquery.mb.YTPlayer.js/wp-content/plugins/wpmbytplayer/css/mb.YTPlayer.css/wp-content/plugins/wpmbytplayer/js/jquery.mb.YTPlayer.jsplugins/wpmbytplayer/js/jquery.mb.YTPlayer.js?ver=plugins/wpmbytplayer/css/mb.YTPlayer.css?ver=HTML / DOM Fingerprints
mbYTPlayerviddata-propertyytplayer