
Auto Last Youtube Video Security & Risk Analysis
wordpress.org/plugins/auto-last-youtube-videoThis plugin provides both Widget and Shortcode to show latest videos from any public Youtube channel.
Is Auto Last Youtube Video Safe to Use in 2026?
Use With Caution
Score 63/100Auto Last Youtube Video has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "auto-last-youtube-video" v1.0.7 plugin exhibits a mixed security posture. While the attack surface appears limited to a single shortcode with no direct authentication checks highlighted, and there are no reported taint flows, several concerning code signals warrant attention. The presence of dangerous functions like `ini_set`, `create_function`, and `unserialize` is a significant red flag, as these can be exploited to execute arbitrary code or lead to deserialization vulnerabilities if user-supplied data is not meticulously handled. Furthermore, a substantial portion of SQL queries are not prepared, and a considerable percentage of output is not properly escaped, increasing the risk of SQL injection and cross-site scripting (XSS) attacks, respectively. The vulnerability history reveals a past medium-severity Cross-Site Request Forgery (CSRF) vulnerability, which, coupled with the lack of nonce checks in the code analysis, suggests a pattern of insufficient input validation and protection against malicious user interactions. The current unpatched CVE is a critical concern and demands immediate attention.
Key Concerns
- Unpatched CVE (Medium severity)
- Dangerous functions found (ini_set, create_function, unserialize)
- Significant percentage of SQL queries not prepared
- Significant percentage of output not properly escaped
- No nonce checks detected
- No capability checks detected on entry points
- Shortcode exists without explicit auth checks reported
Auto Last Youtube Video Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Auto Last Youtube Video <= 1.0.7 - Cross-Site Request Forgery
Auto Last Youtube Video Release Timeline
Auto Last Youtube Video Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Auto Last Youtube Video Attack Surface
Shortcodes 1
WordPress Hooks 2
Maintenance & Trust
Auto Last Youtube Video Maintenance & Trust
Maintenance Signals
Community Trust
Auto Last Youtube Video Alternatives
TechGasp Tube Master
youtube-master
TechGasp Tube Master displays Youtube Playlists or Single Videos with optional Youtube Subscribe Channel button and Google Hangouts.
Awesome Youtube Subscribe
awsome-youtube-subscribe
Here is a short description of the plugin. This should be no more than 150 characters. No markup here.
Feeds for YouTube (YouTube video, channel, and gallery plugin)
feeds-for-youtube
The Feeds for YouTube plugin allows you to display customizable YouTube feeds from any YouTube channel.
Contact Form by BestWebSoft – Advanced WP Contact Form Builder for WordPress
contact-form-plugin
The most powerful and user-friendly WordPress contact form plugin. Create beautiful contact forms, widgets and pages using shortcodes.
Apollo13 Framework Extensions
apollo13-framework-extensions
Adds custom post types, shortcodes and some features that are used in themes built on Apollo13 Framework.
Auto Last Youtube Video Developer Profile
3 plugins · 210 total installs
How We Detect Auto Last Youtube Video
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
widget-titleautolasvideoseeallid="autolasvideoseeall"[embed width=https://www.youtube.com/watch?v=][/embed]