Curator Studio – YouTube – Show videos from channels, playlists and more Security & Risk Analysis

wordpress.org/plugins/curator-studio-youtube

Curate YouTube content like never before.

10 active installs v0.1.3 PHP 5.6+ WP 4.7+ Updated May 2, 2021
streamyoutubeyoutube-galleryyoutube-playeryoutube-playlists
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Curator Studio – YouTube – Show videos from channels, playlists and more Safe to Use in 2026?

Generally Safe

Score 85/100

Curator Studio – YouTube – Show videos from channels, playlists and more has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The "curator-studio-youtube" plugin v0.1.3 demonstrates a generally good security posture based on the provided static analysis. The absence of known vulnerabilities and CVEs in its history is a strong positive indicator. The code also adheres to several best practices, including the exclusive use of prepared statements for all SQL queries, which significantly mitigates the risk of SQL injection. Furthermore, the plugin avoids dangerous functions and file operations, further reducing its attack surface.

However, there are areas of concern that warrant attention. The plugin's output escaping is only 50% proper, meaning that half of its outputs are not being correctly sanitized. This could potentially lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is reflected in these unescaped outputs. Additionally, while there are capability checks present, the absence of nonce checks on any potential entry points (though the static analysis indicates zero unprotected entry points) is a potential weakness. The presence of a single cron event, while not inherently risky, adds to the plugin's overall functionality and thus its potential attack surface that needs careful monitoring.

In conclusion, the "curator-studio-youtube" plugin is in a relatively secure state, particularly concerning database interactions and the lack of historical vulnerabilities. The primary area for improvement lies in ensuring all outputs are properly escaped to prevent XSS. The plugin has a small attack surface and uses prepared statements effectively. Addressing the output escaping issue would significantly enhance its overall security.

Key Concerns

  • Output escaping only 50% proper
  • No nonce checks on entry points
Vulnerabilities
None known

Curator Studio – YouTube – Show videos from channels, playlists and more Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Curator Studio – YouTube – Show videos from channels, playlists and more Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
23 prepared
Unescaped Output
3
3 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
1
Bundled Libraries
0

SQL Query Safety

100% prepared23 total queries

Output Escaping

50% escaped6 total outputs
Attack Surface

Curator Studio – YouTube – Show videos from channels, playlists and more Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actioncstudio_remove_stale_sourcescore\Infra.php:22
actionadmin_menuEntry.php:23
actionwp_footerEntry.php:26
actionrest_api_initEntry.php:32
actioninitEntry.php:34
actionadmin_enqueue_scriptsEntry.php:96
actionadmin_initplatform\Platform.php:28
actionplugins_loadedstart.php:41

Scheduled Events 1

cstudio_remove_stale_sources
Maintenance & Trust

Curator Studio – YouTube – Show videos from channels, playlists and more Maintenance & Trust

Maintenance Signals

WordPress version tested5.7.15
Last updatedMay 2, 2021
PHP min version5.6
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Curator Studio – YouTube – Show videos from channels, playlists and more Developer Profile

plugin.builders

5 plugins · 10K total installs

71
trust score
Avg Security Score
89/100
Avg Patch Time
279 days
View full developer profile
Detection Fingerprints

How We Detect Curator Studio – YouTube – Show videos from channels, playlists and more

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/curator-studio-youtube/ui/dist/js/chunk-vendors.js/wp-content/plugins/curator-studio-youtube/ui/dist/js/chunk-common.js/wp-content/plugins/curator-studio-youtube/ui/dist/js/index.js
Script Paths
dashicons-networking
Version Parameters
curator-studio-youtube/style.css?ver=

HTML / DOM Fingerprints

CSS Classes
cs-e-wcs-editorcs-app-
Data Attributes
data-v-v-bindv-model
JS Globals
csvarscs_editor_varswindow.cserrors
REST Endpoints
/wp-json/curator-studio-youtube/v1/videos
Shortcode Output
<div id="cs-app-
FAQ

Frequently Asked Questions about Curator Studio – YouTube – Show videos from channels, playlists and more