Docus – YouTube Video Playlist Security & Risk Analysis

wordpress.org/plugins/docus

Embedding a YouTube playlist onto any page of your website

10 active installs v1.0.8 PHP + WP 5.0+ Updated Feb 5, 2026
docusyoutubeyoutube-galleryyoutube-playlistyoutube-video
99
A · Safe
CVEs total1
Unpatched0
Last CVEFeb 5, 2026
Download
Safety Verdict

Is Docus – YouTube Video Playlist Safe to Use in 2026?

Generally Safe

Score 99/100

Docus – YouTube Video Playlist has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Feb 5, 2026Updated 3mo ago
Risk Assessment

The docus v1.0.8 plugin exhibits a generally good security posture based on the static analysis provided. It demonstrates strong adherence to secure coding practices, with all identified SQL queries utilizing prepared statements and a very high percentage of output being properly escaped. The plugin also correctly implements nonce and capability checks on its single entry point, indicating an effort to prevent unauthorized actions. Furthermore, the absence of critical or high-severity taint flows suggests that unsanitized user input is not being directly propagated through the codebase in a way that would typically lead to severe vulnerabilities.

However, a significant concern is the historical presence of a medium-severity vulnerability, specifically Cross-Site Scripting (XSS). While the vulnerability is noted as currently unpatched, the reported 'last vulnerability' date of 2026-02-05 18:37:47 seems to be in the future, which is an anomaly and should be investigated. The fact that there was a known XSS vulnerability, even if medium severity, highlights a potential weakness in input sanitization or output escaping for specific scenarios, despite the overall high escape rate reported in the static analysis. The plugin's small attack surface (one shortcode) is a positive, but the historical vulnerability necessitates caution.

In conclusion, docus v1.0.8 demonstrates strengths in its implementation of prepared statements, output escaping, and access control. The minimal attack surface is also a positive. The primary weakness lies in the past XSS vulnerability, which, despite the current static analysis results and the peculiar future date of the last vulnerability, warrants vigilance. Users should verify if this historical vulnerability has been fully remediated in this version or if the static analysis missed a specific input vector for XSS. The anomaly in the 'last vulnerability' date also requires clarification.

Key Concerns

  • Medium severity XSS vulnerability history
  • Anomaly in 'last vulnerability' date
Vulnerabilities
1 published

Docus – YouTube Video Playlist Security Vulnerabilities

CVEs by Year

1 CVE in 2026
2026
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2026-1888medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Docus <= 1.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes

Feb 5, 2026 Patched in 1.0.7 (1d)
Version History

Docus – YouTube Video Playlist Release Timeline

v1.0.8Current
v1.0.7
v1.0.61 CVE
v1.0.51 CVE
v1.0.41 CVE
v1.0.31 CVE
Code Analysis
Analyzed Apr 16, 2026

Docus – YouTube Video Playlist Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
225 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

98% escaped230 total outputs
Attack Surface

Docus – YouTube Video Playlist Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[docusplaylist] includes/class.shortcode.php:27
WordPress Hooks 8
actionadmin_menuadmin/Recommended_Plugins.php:78
actionadmin_enqueue_scriptsadmin/Recommended_Plugins.php:79
actionadmin_initadmin/admin-init.php:32
actionadmin_menuadmin/admin-init.php:33
actionadmin_enqueue_scriptsadmin/admin-init.php:34
actioninitincludes/class.docus.php:28
actioninitincludes/class.docus.php:29
actionwp_enqueue_scriptsincludes/class.docus.php:30
Maintenance & Trust

Docus – YouTube Video Playlist Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 5, 2026
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Docus – YouTube Video Playlist Developer Profile

HT Plugins

25 plugins · 64K total installs

76
trust score
Avg Security Score
96/100
Avg Patch Time
121 days
View full developer profile
Detection Fingerprints

How We Detect Docus – YouTube Video Playlist

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/docus/assets/css/docus.css/wp-content/plugins/docus/assets/js/docus.js
Script Paths
/wp-content/plugins/docus/assets/js/docus.js
Version Parameters
docus/assets/css/docus.css?ver=docus/assets/js/docus.js?ver=

HTML / DOM Fingerprints

CSS Classes
docus-playlist-wrapper
JS Globals
docus_params
Shortcode Output
[docus_playlist
FAQ

Frequently Asked Questions about Docus – YouTube Video Playlist