Arrow Video Feed, Custom Video Channel Feed Security & Risk Analysis

wordpress.org/plugins/add-youtube-feed

Stable tag: 1.1.1 License: GPLv2 or later License URI: http://www.gnu.org/licenses/gpl-2.0.html YouTube Plugin is the best YouTube Feed Plugin to Di …

200 active installs v1.1.1 PHP + WP 4.0+ Updated May 30, 2022
youtubeyoutube-channel-feedyoutube-feedyoutube-mobile-videoyoutube-video
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Arrow Video Feed, Custom Video Channel Feed Safe to Use in 2026?

Generally Safe

Score 85/100

Arrow Video Feed, Custom Video Channel Feed has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "add-youtube-feed" v1.1.1 plugin exhibits a generally good security posture in several key areas. The absence of direct SQL queries, reliance on prepared statements, and zero recorded vulnerabilities in its history are significant strengths. The plugin also demonstrates a minimal attack surface, with only one shortcode identified and no AJAX handlers or REST API routes exposed without proper checks. This suggests a thoughtful approach to development, prioritizing secure coding practices. However, a significant concern arises from the low percentage of properly escaped output (28%). This indicates a substantial risk of Cross-Site Scripting (XSS) vulnerabilities, where user-supplied data could be injected and executed within the browser. Despite the lack of immediate vulnerabilities or taint flows flagged, the widespread potential for unescaped output represents a notable weakness that could be exploited if malicious input is processed through the shortcode or other potential, unanalyzed entry points.

The plugin's vulnerability history is clean, which is positive, but this could also be a reflection of limited historical analysis or that the plugin has not been extensively tested for certain types of vulnerabilities. The absence of nonce checks and capability checks on the identified entry points, coupled with the low output escaping rate, paints a picture of a plugin that, while not demonstrably vulnerable in its current state according to the provided data, has clear areas for improvement in robust input validation and output sanitization. The outdated bundled jQuery library also presents a minor, but present, risk of known exploits affecting that specific version. Overall, the plugin is on a good track due to its low attack surface and lack of direct historical vulnerabilities, but the high rate of unescaped output is a critical area that demands immediate attention to prevent potential XSS attacks.

Key Concerns

  • Low percentage of properly escaped output
  • Bundled outdated library (jQuery v3.1.0)
  • Lack of nonce checks
  • Lack of capability checks
Vulnerabilities
None known

Arrow Video Feed, Custom Video Channel Feed Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Arrow Video Feed, Custom Video Channel Feed Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
71
28 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

jQuery3.1.0

Output Escaping

28% escaped99 total outputs
Attack Surface

Arrow Video Feed, Custom Video Channel Feed Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[arrow_youtube] includes\utbap-shortcode.php:3
WordPress Hooks 11
actionwp_enqueue_scriptsincludes\utbap-enqueue-scripts.php:4
actionadmin_enqueue_scriptsincludes\utbap-enqueue-scripts.php:5
actionadmin_enqueue_scriptsincludes\utbap-enqueue-scripts.php:6
actionadd_meta_boxesincludes\utbap-post-meta-boxes.php:4
actioninitincludes\utbap-post-type.php:4
actionadmin_menuincludes\utbap-post-type.php:5
actionadmin_menuincludes\utbap-post-type.php:6
actionadmin_menuincludes\utbap-post-type.php:7
actionedit_form_after_titleincludes\utbap-post-type.php:107
actionload-post-new.phpincludes\utbap-post-type.php:128
actionsave_postincludes\utbap-save-post.php:4
Maintenance & Trust

Arrow Video Feed, Custom Video Channel Feed Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedMay 30, 2022
PHP min version
Downloads25K

Community Trust

Rating46/100
Number of ratings4
Active installs200
Developer Profile

Arrow Video Feed, Custom Video Channel Feed Developer Profile

Arrow Plugins

5 plugins · 550 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Arrow Video Feed, Custom Video Channel Feed

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/add-youtube-feed/css/youmax-pro.min.css/wp-content/plugins/add-youtube-feed/js/youmax-pro.min.js/wp-content/plugins/add-youtube-feed/js/script.js
Script Paths
js/youmax-pro.min.jsjs/script.js
Version Parameters
youmax-pro.min.css?ver=youmax-pro.min.js?ver=script.js?ver=

HTML / DOM Fingerprints

CSS Classes
youmax-proyl-channel-searchyl-channel-search-inputyl-list-title
HTML Comments
<!--@include /Users/username/Sites/wordpress/wp-content/plugins/arrow-youtube-feed/public/views/templates/youmax-template1.php--><!--@include /Users/username/Sites/wordpress/wp-content/plugins/arrow-youtube-feed/public/views/templates/youmax-template2.php--><!--@include /Users/username/Sites/wordpress/wp-content/plugins/arrow-youtube-feed/public/views/templates/youmax-template3.php--><!--@include /Users/username/Sites/wordpress/wp-content/plugins/arrow-youtube-feed/public/views/templates/youmax-template4.php-->+2 more
Data Attributes
data-channel_linkdata-videos_to_showdata-channel_styledata-video_display_modedata-hide_headerdata-load_more+35 more
JS Globals
utbap_youtube_channel_linkutbap_videos_to_showutbap_auto_playutbap_sorting_orderutbap_loading_mechanismutbap_default_tab+35 more
Shortcode Output
<div id="your-page-column" class="not-a-part-of-youmax-plugin"> <div id="ymax" class="youmax-pro"></div> </div>
FAQ

Frequently Asked Questions about Arrow Video Feed, Custom Video Channel Feed