Awesome Youtube Subscribe Security & Risk Analysis

wordpress.org/plugins/awsome-youtube-subscribe

Here is a short description of the plugin. This should be no more than 150 characters. No markup here.

10 active installs v2.0 PHP + WP 4.6+ Updated Oct 25, 2018
shareshortcodesubscribewidgetyoutube
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Awesome Youtube Subscribe Safe to Use in 2026?

Generally Safe

Score 85/100

Awesome Youtube Subscribe has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The plugin 'awsome-youtube-subscribe' v2.0 exhibits a mixed security posture. On the positive side, it has no known vulnerabilities, does not perform file operations or external HTTP requests, and all identified SQL queries utilize prepared statements. The attack surface is also relatively small, with only one shortcode identified and no AJAX handlers or REST API routes that appear unprotected. The absence of any critical or high severity taint analysis findings is also a good sign.

However, there are significant areas of concern. The most prominent is the low percentage of properly escaped output (29%), indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. Coupled with the complete absence of nonce checks and capability checks, any user-supplied data that makes its way into output without proper sanitization could be exploited. The lack of capability checks is particularly worrying as it implies that any user, regardless of their role, could potentially trigger functionality that might lead to unintended consequences if XSS is achievable.

Given the clean vulnerability history, it might suggest that the plugin has historically been well-maintained or that the limited scope of its functionality has not attracted attacks. However, the current code analysis reveals potential weaknesses that could be exploited. The strengths lie in the absence of direct SQL injection risks and external dependencies, but the weakness in output escaping and lack of authentication/authorization checks on entry points are substantial risks that need immediate attention.

Key Concerns

  • Low output escaping percentage
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Awesome Youtube Subscribe Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Awesome Youtube Subscribe Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
29
12 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

29% escaped41 total outputs
Attack Surface

Awesome Youtube Subscribe Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[Awesome-youtube-subscribe] includes\sm-youtube-subscription-shortcode.php:248
WordPress Hooks 3
actionwidgets_initeasy-youtube-subscribe.php:107
actionadmin_menuincludes\sm-youtube-subscription-shortcode.php:14
actionadmin_initincludes\sm-youtube-subscription-shortcode.php:15
Maintenance & Trust

Awesome Youtube Subscribe Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.32
Last updatedOct 25, 2018
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Awesome Youtube Subscribe Developer Profile

Raihanul Islam

13 plugins · 370 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Awesome Youtube Subscribe

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
g-ytsubscribe
Data Attributes
data-channeliddata-layoutdata-themedata-count
Shortcode Output
[Awesome-youtube-subscribe]
FAQ

Frequently Asked Questions about Awesome Youtube Subscribe