
Wubtitle Security & Risk Analysis
wordpress.org/plugins/wubtitleWubtitle is a plugin that generates subtitles and transcript of uploaded videos in media library, Youtube and Vimeo videos.
Is Wubtitle Safe to Use in 2026?
Generally Safe
Score 85/100Wubtitle has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'wubtitle' plugin version 1.2.4 demonstrates a generally positive security posture with several good practices in place. The complete absence of known CVEs and a consistent use of prepared statements for all SQL queries are strong indicators of responsible development. Furthermore, the plugin exhibits a high rate of output escaping, which is crucial for preventing cross-site scripting vulnerabilities. However, there are notable areas of concern. The presence of two unprotected entry points, specifically an AJAX handler and a REST API route lacking proper authorization checks, presents a direct attack vector. While taint analysis did not reveal critical or high severity issues, the two flows with unsanitized paths are a cause for concern and warrant further investigation. The plugin's vulnerability history is clean, suggesting recent development efforts have been security-conscious. Overall, 'wubtitle' benefits from a lack of historical vulnerabilities and robust SQL and output handling. Nevertheless, the unprotected AJAX and REST API endpoints are significant weaknesses that expose the plugin to potential unauthorized actions and require immediate attention.
Key Concerns
- AJAX handler without auth checks
- REST API route without permission callbacks
- Flows with unsanitized paths
Wubtitle Security Vulnerabilities
Wubtitle Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Wubtitle Attack Surface
AJAX Handlers 20
REST API Routes 6
Shortcodes 1
WordPress Hooks 49
Scheduled Events 1
Maintenance & Trust
Wubtitle Maintenance & Trust
Maintenance Signals
Community Trust
Wubtitle Alternatives
JW Player for WordPress
jw-player-7-for-wp
JW Player for WordPress enables you to publish videos on your WordPress posts and pages using the most popular video player on the web.
WP Amara Shortcode
wp-amara-shortcode
A simple wordpress plugin to enable Amara.org shortcode
XML Sitemap Generator for Google
google-sitemap-generator
Generate multiple types of sitemaps to improve SEO and get your website indexed quickly.
Sitemap Generator Professional
mb-sitemap-generator
An easy to use XML sitemap generator with support for image and video sitemaps for WordPress.
Subtitles
subtitles
Add subtitles into your WordPress posts, pages, custom post types, and themes. No coding required. Simply activate Subtitles and you're ready.
Wubtitle Developer Profile
1 plugin · 40 total installs
How We Detect Wubtitle
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wubtitle/assets/css/payment_template.css/wp-content/plugins/wubtitle/assets/payment/payment_template.js/wp-content/plugins/wubtitle/assets/payment/change_plan_script.jshttps://fonts.googleapis.com/css?family=Days+One|Open+Sans&display=swaphttps://js.stripe.com/v3/https://kit.fontawesome.com/b78c2a4b89.jswubtitle/assets/css/payment_template.css?ver=wubtitle/assets/payment/payment_template.js?ver=wubtitle/assets/payment/change_plan_script.js?ver=HTML / DOM Fingerprints
WP_GLOBALS