
Docus – YouTube Video Playlist Security & Risk Analysis
wordpress.org/plugins/docusEmbedding a YouTube playlist onto any page of your website
Is Docus – YouTube Video Playlist Safe to Use in 2026?
Generally Safe
Score 99/100Docus – YouTube Video Playlist has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The docus v1.0.8 plugin exhibits a generally good security posture based on the static analysis provided. It demonstrates strong adherence to secure coding practices, with all identified SQL queries utilizing prepared statements and a very high percentage of output being properly escaped. The plugin also correctly implements nonce and capability checks on its single entry point, indicating an effort to prevent unauthorized actions. Furthermore, the absence of critical or high-severity taint flows suggests that unsanitized user input is not being directly propagated through the codebase in a way that would typically lead to severe vulnerabilities.
However, a significant concern is the historical presence of a medium-severity vulnerability, specifically Cross-Site Scripting (XSS). While the vulnerability is noted as currently unpatched, the reported 'last vulnerability' date of 2026-02-05 18:37:47 seems to be in the future, which is an anomaly and should be investigated. The fact that there was a known XSS vulnerability, even if medium severity, highlights a potential weakness in input sanitization or output escaping for specific scenarios, despite the overall high escape rate reported in the static analysis. The plugin's small attack surface (one shortcode) is a positive, but the historical vulnerability necessitates caution.
In conclusion, docus v1.0.8 demonstrates strengths in its implementation of prepared statements, output escaping, and access control. The minimal attack surface is also a positive. The primary weakness lies in the past XSS vulnerability, which, despite the current static analysis results and the peculiar future date of the last vulnerability, warrants vigilance. Users should verify if this historical vulnerability has been fully remediated in this version or if the static analysis missed a specific input vector for XSS. The anomaly in the 'last vulnerability' date also requires clarification.
Key Concerns
- Medium severity XSS vulnerability history
- Anomaly in 'last vulnerability' date
Docus – YouTube Video Playlist Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Docus <= 1.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
Docus – YouTube Video Playlist Release Timeline
Docus – YouTube Video Playlist Code Analysis
Output Escaping
Docus – YouTube Video Playlist Attack Surface
Shortcodes 1
WordPress Hooks 8
Maintenance & Trust
Docus – YouTube Video Playlist Maintenance & Trust
Maintenance Signals
Community Trust
Docus – YouTube Video Playlist Alternatives
Video Gallery – YouTube Playlist, Channel Gallery by YotuWP
yotuwp-easy-youtube-embed
Modern responsive YouTube video gallery helps your website getting noticed from visitors, increase the reach and stand out from the competitors.
GS YouTube Gallery – Video Feed, Channel Playlist & YouTube Slider
gs-youtube-gallery
Create a Stunning & Responsive Video Gallery for Channel or Playlist Videos.
YourChannel: Everything you want in a YouTube plugin.
yourchannel
Setup beautiful YouTube feed streams with 1 copy paste & 2 clicks. Displays banner, uploads, playlists and more (All optional).
Automatic YouTube Gallery
automatic-youtube-gallery
Build dynamic video galleries by simply adding a YouTube USERNAME, CHANNEL, PLAYLIST, SEARCH KEYWORDS, or a custom list of video URLs.
FancyTube – Video Gallery, Video Slider, and Playlist Slider for YouTube
video-gallery-playlist
Create stunning YouTube video galleries, sliders, and playlists. Perfect for bloggers, vloggers, and businesses.
Docus – YouTube Video Playlist Developer Profile
25 plugins · 64K total installs
How We Detect Docus – YouTube Video Playlist
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/docus/assets/css/docus.css/wp-content/plugins/docus/assets/js/docus.js/wp-content/plugins/docus/assets/js/docus.jsdocus/assets/css/docus.css?ver=docus/assets/js/docus.js?ver=HTML / DOM Fingerprints
docus-playlist-wrapperdocus_params[docus_playlist