
Chromeless YouTube Security & Risk Analysis
wordpress.org/plugins/chromeless-youtubeThis chromeless YouTube player enables you to easily display videos on your site. Each player instance displays a different video and can be resized.
Is Chromeless YouTube Safe to Use in 2026?
Generally Safe
Score 85/100Chromeless YouTube has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "chromeless-youtube" v1.01 plugin exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices regarding SQL queries, utilizing prepared statements exclusively, and has no recorded vulnerability history, suggesting a generally stable codebase. It also has a very small attack surface with only one entry point and no known CVEs. However, significant concerns arise from the static analysis. The use of the `create_function` function is a critical red flag, as it can lead to arbitrary code execution if not handled with extreme care. Furthermore, a substantial portion of its output (85%) is not properly escaped, creating a high risk of Cross-Site Scripting (XSS) vulnerabilities. The lack of nonce checks and capability checks on its single entry point (the shortcode) is also a significant oversight, potentially allowing unauthorized actions or information disclosure if the shortcode can be exploited.
Key Concerns
- Use of dangerous function create_function
- High percentage of unescaped output (XSS risk)
- Missing nonce checks on entry points
- Missing capability checks on entry points
Chromeless YouTube Security Vulnerabilities
Chromeless YouTube Code Analysis
Dangerous Functions Found
Output Escaping
Chromeless YouTube Attack Surface
Shortcodes 1
WordPress Hooks 1
Maintenance & Trust
Chromeless YouTube Maintenance & Trust
Maintenance Signals
Community Trust
Chromeless YouTube Alternatives
Gosign – Youtube Video Player Block
gosign-youtube-video-player-block
Fügen Sie einmal einen Youtube-Videoplayerblock mit benutzerdefiniertem Splash-Bild anstelle des Youtube-Standards hinzu und können Sie auch Optionen …
Video Player Pro
video-player-pro
Change all site videos with one click - Has YouTube skin - Create unlimited playlists - Subtitle Support (SRT) - Multi Quality Support - Video Element …
AutoCraft Player
autocraft-player
AutoCraft Player: The Ultimate Customizable Audio & Video Experience for WordPress
All-in-One Video Gallery
all-in-one-video-gallery
The ultimate video player & video gallery plugin for YouTubers, Video Bloggers, Course Creators, Podcasters, and anyone embedding videos on websites.
Wonder Video Embed
wonderplugin-video-embed
Embed MP4, Youtube, Vimeo, Wistia videos to the sidebar widget, WordPress posts and pages.
Chromeless YouTube Developer Profile
5 plugins · 70 total installs
How We Detect Chromeless YouTube
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/chromeless-youtube/chromeless.swfHTML / DOM Fingerprints
widget_chromelessTitle Input FieldVideo Source Input FieldSource Width Input FieldSource Height Input Field+2 moredataflashVarsqualitywmodeswfversionexpressinstall+1 more[chromeless id=width=height=autoplay=