
Download buttons for Youtube videos Security & Risk Analysis
wordpress.org/plugins/audio-video-download-buttons-for-youtube[ โ ๐๐๐๐๐๐ ๐๐๐๐๐๐๐ b๐ ๐ซ๐๐๐๐ ] Add download buttons for any Youtube video with Shortcodes
Is Download buttons for Youtube videos Safe to Use in 2026?
Generally Safe
Score 100/100Download buttons for Youtube videos has a strong security track record. Known vulnerabilities have been patched promptly.
The "audio-video-download-buttons-for-youtube" plugin, version 1.20, exhibits a mixed security posture. While it has no known unpatched vulnerabilities and a relatively low number of total CVEs, the static analysis reveals some concerning aspects. The presence of dangerous functions like `shell_exec` and `unserialize` is a significant red flag, as these can be exploited for remote code execution or data manipulation if not handled with extreme care. Furthermore, a concerning percentage of output is not properly escaped, increasing the risk of cross-site scripting (XSS) vulnerabilities. The taint analysis shows one flow with a high severity, indicating a potential for serious security issues, and a significant number of flows with unsanitized paths, which could lead to directory traversal or other file-related attacks.
The plugin's vulnerability history, specifically a past medium severity XSS vulnerability, reinforces the concern about output sanitization. While there are no currently unpatched CVEs, the presence of past XSS issues suggests a recurring weakness in input validation and output encoding. The limited attack surface (0 entry points) is a positive, but it does not negate the risks identified in the code signals and taint analysis. In conclusion, while the plugin appears to have addressed past critical issues, the use of dangerous functions, insufficient output escaping, and high-severity taint flows present notable risks that require careful consideration and potentially remediation.
Key Concerns
- Dangerous functions: shell_exec, unserialize found
- High severity taint flow detected
- Significant unsanitized paths in taint flows
- Less than 50% of outputs properly escaped
- Past medium severity XSS vulnerability history
- Low number of capability checks
Download buttons for Youtube videos Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Download buttons for Youtube videos <= 1.03 - Reflected Cross-Site Scripting
Download buttons for Youtube videos Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Download buttons for Youtube videos Attack Surface
WordPress Hooks 35
Maintenance & Trust
Download buttons for Youtube videos Maintenance & Trust
Maintenance Signals
Community Trust
Download buttons for Youtube videos Alternatives
Video Gallery โ YouTube Playlist, Channel Gallery by YotuWP
yotuwp-easy-youtube-embed
Modern responsive YouTube video gallery helps your website getting noticed from visitors, increase the reach and stand out from the competitors.
SocialFeeds
socialfeeds
YouTube feeds for WordPress with simple Setup and Settings options.
Video Playlist For YouTube
video-playlist-for-youtube
Video Playlist for Youtube is a very nifty responsive video gallery plugin that helps you put videos and playlist wherever you need.
WP YouTube Player
wp-youtube-player
Insert Youtube Videos on WordPress blog.
Easy Support Videos โ Embed videos in the admin
easy-support-videos
Easy Support Videos for embedding helpful tutorials, training videos, and screencasts in the Admin dashboard. Works with YouTube, Vimeo, Wistia, Video …
Download buttons for Youtube videos Developer Profile
16 plugins ยท 51K total installs
How We Detect Download buttons for Youtube videos
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/audio-video-download-buttons-for-youtube/assets/styles.css/wp-content/plugins/audio-video-download-buttons-for-youtube/assets/scripts.js/wp-content/plugins/audio-video-download-buttons-for-youtube/assets/scripts.jsHTML / DOM Fingerprints
dbfy-download-wrapperdownloadButtondownloadButtonsdata-iddata-textdata-minutesdbfy_download<div class="dbfy-download-wrapper"><a href="https://savefrom.net/?url=<a class="downloadButton"<div class="downloadButtons"></div>