Enhanced YouTube Embed Security & Risk Analysis

wordpress.org/plugins/enhanced-youtube-embed

Set the start, end, language, playback speed, loop, and more. Supports blocks and shortcodes. Create TikTok like videos from any YouTube video too.

10 active installs v2.2.0 PHP 7.4+ WP 5.8+ Updated Mar 7, 2026
blockshortcodetiktokvideoyoutube
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Enhanced YouTube Embed Safe to Use in 2026?

Generally Safe

Score 100/100

Enhanced YouTube Embed has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "enhanced-youtube-embed" v2.2.0 plugin exhibits a generally strong security posture based on the provided static analysis. It demonstrates excellent practices by not using dangerous functions, all SQL queries are properly prepared, and output escaping is nearly perfect with 96% of outputs handled securely. Furthermore, the absence of file operations, external HTTP requests, and known vulnerabilities (CVEs) are significant strengths. The plugin also shows an awareness of security by including nonce checks. However, a notable concern is the lack of capability checks on its single AJAX handler, meaning any authenticated user could potentially interact with it without proper authorization. While the attack surface is small and the taint analysis revealed no issues, this single unprotected entry point represents a potential weak link.

Key Concerns

  • AJAX handler without capability checks
Vulnerabilities
None known

Enhanced YouTube Embed Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Enhanced YouTube Embed Release Timeline

v2.2.0Current
v2.1.0
v2.0.0
v1.0.0
Code Analysis
Analyzed Mar 17, 2026

Enhanced YouTube Embed Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
25 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

96% escaped26 total outputs
Attack Surface

Enhanced YouTube Embed Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 1

authwp_ajax_yee_previewadmin\shortcode-editor.php:108

Shortcodes 1

[enhanced-youtube-embed] youtube-enhanced-embed.php:346
WordPress Hooks 4
actionadmin_menuadmin\shortcode-editor.php:26
actionadmin_enqueue_scriptsadmin\shortcode-editor.php:70
actioninityoutube-enhanced-embed.php:145
actioninityoutube-enhanced-embed.php:397
Maintenance & Trust

Enhanced YouTube Embed Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 7, 2026
PHP min version7.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Enhanced YouTube Embed Developer Profile

Steve Puddick

6 plugins · 1K total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Enhanced YouTube Embed

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/enhanced-youtube-embed/build/index.css/wp-content/plugins/enhanced-youtube-embed/build/index.js
Script Paths
/wp-content/plugins/enhanced-youtube-embed/build/index.js
Version Parameters
enhanced-youtube-embed/build/index.css?ver=enhanced-youtube-embed/build/index.js?ver=

HTML / DOM Fingerprints

CSS Classes
wp-block-create-block-youtube-enhanced-embedyee-video-iframe
Data Attributes
data-playback-speed
Shortcode Output
<figure class="wp-block-embed wp-block-create-block-youtube-enhanced-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper"><iframe class="yee-video-iframe"<figcaption class="wp-element-caption">
FAQ

Frequently Asked Questions about Enhanced YouTube Embed