depscope
Packages
IntegrateAPI DocsCuratorBenchmarkCoverage
Sign inGet API access
depscope/composer/wwbn/avideo

wwbn/avideo

composerv29.0

Audio Video Platform

License proprietaryproprietary18 versions45 deps
WWBN/AVideo
40
/ 100
Health
do not use

wwbn/avideo has critical vulnerabilities — do not use

  • Moderate health score (40/100) — verify manually
  • 8 high severity vulnerabilities
  • 1 critical vulnerabilities
Health breakdown0 – 100
25/25
maintenance
0/20
popularity
0/25
security
9/15
maturity
6/15
community
Vulnerabilities
19
1 critical8 high10 medium
Advisories (19)
SeverityIDSummaryFixed in
mediumGHSA-52hf-63q4-r926WWBN AVideo has an Unauthenticated Information Disclosure via git.json.php Exposes Developer Emails and Deployed Version—
mediumGHSA-5879-4fmr-xwf2WWBN AVideo has an incomplete fix for CVE-2026-33293: Path Traversal—
highGHSA-6rc6-p838-686fWWBN AVideo has a Path Traversal in Locale Save Endpoint Enables Arbitrary PHP File Write to Any Web-Accessible Directory (RCE)—
mediumGHSA-793q-xgj6-7frpWWBN AVideo has an incomplete fix for CVE-2026-33039: SSRF—
mediumGHSA-8pv3-29pp-pf8fWWBN AVideo has Stored XSS via Unanchored Duration Regex in Video Encoder Receiver—
mediumGHSA-8qm8-g55h-xmqrWWBN AVideo is missing CSRF protection in objects/commentDelete.json.php enables mass comment deletion against moderators and content creators—
highGHSA-ccq9-r5cw-5hwqWWBN AVideo has CORS Origin Reflection with Credentials on Sensitive API Endpoints Enables Cross-Origin Account Takeover—
highGHSA-ff5q-cc22-fgp4WWBN AVideo has a CORS Origin Reflection Bypass via plugin/API/router.php and allowOrigin(true) Exposes Authenticated API Responses—
highGHSA-ffw8-fwxp-h64wWWBN AVideo has Multiple CSRF Vulnerabilities in Admin JSON Endpoints (Category CRUD, Plugin Update Script)—
mediumGHSA-gpgp-w4x2-h3h7WWBN AVideo has an IDOR in Live Restreams list.json.php Exposes Other Users' Stream Keys and OAuth Tokens—
criticalGHSA-gph2-j4c9-vhhrWWBN AVideo YPTSocket WebSocket Broadcast Relay Leads to Unauthenticated Cross-User JavaScript Execution via Client-Side eval() Sinks—
mediumGHSA-hg7g-56h5-5pqrCAPTCHA Bypass in WWBN/AVideo via Attacker-Controlled Length Parameter and Missing Token Invalidation on Failure—
highGHSA-j432-4w3j-3w8jWWBN AVideo has a SSRF via same-domain hostname with alternate port bypasses isSSRFSafeURL—
mediumGHSA-m63r-m9jh-3vc6WWBN AVideo has an Incomplete fix: Directory traversal bypass via query string in ReceiveImage downloadURL parameters—
mediumGHSA-m7r8-6q9j-m2hcWWBN AVideo has an incomplete fix for CVE-2026-33500: XSS—
highGHSA-pq8p-wc4f-vg7jWWBN AVideo has an incomplete fix for CVE-2026-33502: Command Injection—
highGHSA-vvfw-4m39-fjqfWWBN AVideo has CSRF in configurationUpdate.json.php Enables Full Site Configuration Takeover Including Encoder URL and SMTP Credentials—
mediumGHSA-x2pw-9c38-cp2jWWBN AVideo: Missing CSRF Protection on State-Changing JSON Endpoints Enables Forced Comment Creation, Vote Manipulation, and Category Asset Deletion—
highGHSA-xr6f-h4x7-r6qpWWBN AVideo: RCE cause by clonesite plugin—

Health History

Dependency Tree

License Audit

Dependencies (45)
phpext-curlext-jsonezyang/htmlpurifiergoogle/apiclientgoogle/apiclient-servicesgoogle/authguzzlehttp/guzzleguzzlehttp/psr7hybridauth/hybridauthjames-heinrich/getid3monolog/monologphpmailer/phpmailerpsr/cachepsr/http-messagesingpolyma/openpgp-phpaws/aws-sdk-phpgliterd/backblaze-b2paypal/rest-api-sdk-phppaypal/paypal-payouts-sdkpaypal/paypal-checkout-sdkemojione/assetsmervick/emojioneareaemojione/emojioneabraham/twitteroauthsymfony/http-clientnorkunas/onesignal-php-apistripe/stripe-phpsymfony/translationamphp/ampscssphp/scssphpvimeo/vimeo-apiphpseclib/phpseclibbunnycdn/storagechillerlan/php-qrcodeerusev/parsedownspomky-labs/otphpchristian-riesen/base32react/socketreact/event-loopelephantio/elephant.ioiamcal/sql-parserratchet/pawlzircote/swagger-phpauthorizenet/authorizenet
API access

Get this data programmatically — free, no authentication.

curl https://depscope.dev/api/check/composer/wwbn/avideo

Last updated · 2026-04-07T15:55:24+00:00

DepScope

Package intelligence for AI agents. 19 ecosystems.

Resources
API DocumentationHallucination BenchmarkFor EnterpriseSwagger / OpenAPIPopular PackagesCoverageAI Plugin SetupWatch the pitch (60s)
Legal
Legal hubPrivacy PolicyTerms of ServiceCookie PolicyAcceptable UseAttributionDPASub-processorsSecurityImprintContact中文
© 2026 Cuttalo srl — Italy · VAT IT03242390734Built for AI agents