
Arrow Video Feed, Custom Video Channel Feed Security & Risk Analysis
wordpress.org/plugins/add-youtube-feedStable tag: 1.1.1 License: GPLv2 or later License URI: http://www.gnu.org/licenses/gpl-2.0.html YouTube Plugin is the best YouTube Feed Plugin to Di …
Is Arrow Video Feed, Custom Video Channel Feed Safe to Use in 2026?
Generally Safe
Score 85/100Arrow Video Feed, Custom Video Channel Feed has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "add-youtube-feed" v1.1.1 plugin exhibits a generally good security posture in several key areas. The absence of direct SQL queries, reliance on prepared statements, and zero recorded vulnerabilities in its history are significant strengths. The plugin also demonstrates a minimal attack surface, with only one shortcode identified and no AJAX handlers or REST API routes exposed without proper checks. This suggests a thoughtful approach to development, prioritizing secure coding practices. However, a significant concern arises from the low percentage of properly escaped output (28%). This indicates a substantial risk of Cross-Site Scripting (XSS) vulnerabilities, where user-supplied data could be injected and executed within the browser. Despite the lack of immediate vulnerabilities or taint flows flagged, the widespread potential for unescaped output represents a notable weakness that could be exploited if malicious input is processed through the shortcode or other potential, unanalyzed entry points.
The plugin's vulnerability history is clean, which is positive, but this could also be a reflection of limited historical analysis or that the plugin has not been extensively tested for certain types of vulnerabilities. The absence of nonce checks and capability checks on the identified entry points, coupled with the low output escaping rate, paints a picture of a plugin that, while not demonstrably vulnerable in its current state according to the provided data, has clear areas for improvement in robust input validation and output sanitization. The outdated bundled jQuery library also presents a minor, but present, risk of known exploits affecting that specific version. Overall, the plugin is on a good track due to its low attack surface and lack of direct historical vulnerabilities, but the high rate of unescaped output is a critical area that demands immediate attention to prevent potential XSS attacks.
Key Concerns
- Low percentage of properly escaped output
- Bundled outdated library (jQuery v3.1.0)
- Lack of nonce checks
- Lack of capability checks
Arrow Video Feed, Custom Video Channel Feed Security Vulnerabilities
Arrow Video Feed, Custom Video Channel Feed Code Analysis
Bundled Libraries
Output Escaping
Arrow Video Feed, Custom Video Channel Feed Attack Surface
Shortcodes 1
WordPress Hooks 11
Maintenance & Trust
Arrow Video Feed, Custom Video Channel Feed Maintenance & Trust
Maintenance Signals
Community Trust
Arrow Video Feed, Custom Video Channel Feed Alternatives
SocialFeeds
socialfeeds
YouTube feeds for WordPress with simple Setup and Settings options.
GS YouTube Gallery – Video Feed, Channel Playlist & YouTube Slider
gs-youtube-gallery
Create a Stunning & Responsive Video Gallery for Channel or Playlist Videos.
Feeds for YouTube (YouTube video, channel, and gallery plugin)
feeds-for-youtube
The Feeds for YouTube plugin allows you to display customizable YouTube feeds from any YouTube channel.
Social Slider Feed
instagram-slider-widget
Display Instagram, Facebook and YouTube feeds in widgets, posts, pages, or anywhere else on your website.
Video Gallery – YouTube Playlist, Channel Gallery by YotuWP
yotuwp-easy-youtube-embed
Modern responsive YouTube video gallery helps your website getting noticed from visitors, increase the reach and stand out from the competitors.
Arrow Video Feed, Custom Video Channel Feed Developer Profile
5 plugins · 550 total installs
How We Detect Arrow Video Feed, Custom Video Channel Feed
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/add-youtube-feed/css/youmax-pro.min.css/wp-content/plugins/add-youtube-feed/js/youmax-pro.min.js/wp-content/plugins/add-youtube-feed/js/script.jsjs/youmax-pro.min.jsjs/script.jsyoumax-pro.min.css?ver=youmax-pro.min.js?ver=script.js?ver=HTML / DOM Fingerprints
youmax-proyl-channel-searchyl-channel-search-inputyl-list-title<!--@include /Users/username/Sites/wordpress/wp-content/plugins/arrow-youtube-feed/public/views/templates/youmax-template1.php--><!--@include /Users/username/Sites/wordpress/wp-content/plugins/arrow-youtube-feed/public/views/templates/youmax-template2.php--><!--@include /Users/username/Sites/wordpress/wp-content/plugins/arrow-youtube-feed/public/views/templates/youmax-template3.php--><!--@include /Users/username/Sites/wordpress/wp-content/plugins/arrow-youtube-feed/public/views/templates/youmax-template4.php-->+2 moredata-channel_linkdata-videos_to_showdata-channel_styledata-video_display_modedata-hide_headerdata-load_more+35 moreutbap_youtube_channel_linkutbap_videos_to_showutbap_auto_playutbap_sorting_orderutbap_loading_mechanismutbap_default_tab+35 more<div id="your-page-column" class="not-a-part-of-youmax-plugin">
<div id="ymax" class="youmax-pro"></div>
</div>