
AWEOS YouTube load per click Security & Risk Analysis
wordpress.org/plugins/aweos-youtube-iframe-load-per-clickThis Plugin prevents the auto loading from YouTube iframes. It will be loaded after the user permits it.
Is AWEOS YouTube load per click Safe to Use in 2026?
Generally Safe
Score 92/100AWEOS YouTube load per click has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "aweos-youtube-iframe-load-per-click" plugin, in version 1.0.4, presents a generally positive security posture based on the static analysis. The complete absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the potential attack surface. Furthermore, the code signals indicate no dangerous functions, all SQL queries are properly prepared, and there are no file operations or external HTTP requests, which are all strong security practices. The lack of vulnerability history also suggests a stable and secure codebase over time.
However, a key concern is the complete absence of nonce checks and capability checks. While the current entry points are zero, this lack of built-in security mechanisms means that if any new entry points are introduced in future versions without proper authentication, the plugin would be immediately vulnerable. Additionally, 67% of output is properly escaped, which is decent, but the remaining 33% (one output) could potentially lead to cross-site scripting (XSS) vulnerabilities if user-controlled data is involved and not properly handled.
In conclusion, the plugin demonstrates a good foundation of secure coding practices. Its limited attack surface and lack of known vulnerabilities are strengths. The primary weakness lies in the absence of fundamental security checks like nonces and capability checks, which represents a potential future risk if the plugin evolves. The small amount of unescaped output is a minor concern that should be addressed.
Key Concerns
- No nonce checks
- No capability checks
- Some unescaped output (1/3)
AWEOS YouTube load per click Security Vulnerabilities
AWEOS YouTube load per click Code Analysis
Output Escaping
AWEOS YouTube load per click Attack Surface
WordPress Hooks 4
Maintenance & Trust
AWEOS YouTube load per click Maintenance & Trust
Maintenance Signals
Community Trust
AWEOS YouTube load per click Alternatives
WP DSGVO Tools (GDPR)
shapepress-dsgvo
WP DSGVO Tools (GDPR) by legalweb.io help you to fulfill the GDPR (DSGVO) compliance guidance (GDPR)
DSGVO All in one for WP
dsgvo-all-in-one-for-wp
An All in One GDPR Plugin for everything! Responsive Cookie Notice - Imprint & Privacy Policy Generator - integrate external Services GDPR complia …
DSGVO Youtube
dsgvo-youtube
With this plugin you can add your youtube videos as according to the gdpr regulations
exovia YouTube DSGVO
exovia-youtube-dsgvo
exovia YouTube DSGVO enables you to integrate YouTube Videos in a privacy compliant manner that respects the privacy of your visitors.
GDPR Cookie Compliance – Cookie Banner, Cookie Consent, Cookie Notice for CCPA, EU Cookie Law
gdpr-cookie-compliance
Cookie notice banner for GDPR, CCPA, EU cookie law, data protection and privacy regulations and other cookie law and consent notice requirements on yo …
AWEOS YouTube load per click Developer Profile
10 plugins · 6K total installs
How We Detect AWEOS YouTube load per click
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/aweos-youtube-iframe-load-per-click/script.js/wp-content/plugins/aweos-youtube-iframe-load-per-click/style.css/wp-content/plugins/aweos-youtube-iframe-load-per-click/script.jsaweos-youtube-iframe-load-per-click/script.js?ver=aweos-youtube-iframe-load-per-click/style.css?ver=HTML / DOM Fingerprints
awyt-videodata-src