MacOS security protections can easily be bypassed with ‘synthetic’ clicks(techcrunch.com)
techcrunch.com
MacOS security protections can easily be bypassed with ‘synthetic’ clicks
https://techcrunch.com/2019/06/03/macos-security-flaw-synthetic-clicks/
Yes - plugins add risk because they are dynamic and have an uncontrolled upgrade path with potentially different or non-existent signing systems. That is why plugins and extensions are not allowed on the more-controlled and newer iOS.
I doubt this gets addressed very quickly - if anything it is easier and cheaper to audit all VLC extensions and introduce a signing system. Or to kill VLC's trusted cert/status altogether and treat it as a custom dev app - install-at-your-own-risk.