
Feeds for YouTube (YouTube video, channel, and gallery plugin) Security & Risk Analysis
wordpress.org/plugins/feeds-for-youtubeThe Feeds for YouTube plugin allows you to display customizable YouTube feeds from any YouTube channel.
Is Feeds for YouTube (YouTube video, channel, and gallery plugin) Safe to Use in 2026?
Generally Safe
Score 95/100Feeds for YouTube (YouTube video, channel, and gallery plugin) has a strong security track record. Known vulnerabilities have been patched promptly.
The "feeds-for-youtube" v2.6.3 plugin exhibits a mixed security posture. On the positive side, it demonstrates a commitment to secure coding by avoiding dangerous functions, having no reported critical or high severity CVEs, and utilizing prepared statements for a significant portion of its SQL queries. The presence of a substantial number of nonce and capability checks also suggests an awareness of WordPress security best practices. However, there are significant concerns. The plugin exposes a large attack surface with 61 AJAX handlers, and a concerning 17 of these lack any authentication checks. While no critical or high severity taint flows were found, 5 out of 17 analyzed flows had unsanitized paths, which could lead to vulnerabilities if exploited. The vulnerability history indicates a pattern of medium severity issues, primarily related to Missing Authorization and Cross-site Scripting. The fact that the last known vulnerability was recent (2025-11-06) and there are currently no unpatched CVEs is a good sign, but the recurring nature of these vulnerability types warrants attention.
Key Concerns
- Significant number of AJAX handlers without auth checks
- Flows with unsanitized paths detected
- History of medium severity CVEs (Missing Auth, XSS)
- Less than ideal output escaping percentage
- Potentially vulnerable SQL queries (50% not prepared)
Feeds for YouTube (YouTube video, channel, and gallery plugin) Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
Feeds for YouTube <= 2.4.0 - Missing Authorization
Feeds for YouTube (YouTube video, channel, and gallery plugin) <= 2.2.1 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting
Feeds for YouTube <= 2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Smash Balloon Plugins (Various Versions) - Reflected Cross-Site Scripting
Feeds for YouTube (YouTube video, channel, and gallery plugin) Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Feeds for YouTube (YouTube video, channel, and gallery plugin) Attack Surface
AJAX Handlers 61
Shortcodes 1
WordPress Hooks 85
Scheduled Events 8
Maintenance & Trust
Feeds for YouTube (YouTube video, channel, and gallery plugin) Maintenance & Trust
Maintenance Signals
Community Trust
Feeds for YouTube (YouTube video, channel, and gallery plugin) Alternatives
GS YouTube Gallery – Video Feed, Channel Playlist & YouTube Slider
gs-youtube-gallery
Create a Stunning & Responsive Video Gallery for Channel or Playlist Videos.
Aklamator – Youtube Your Blog
aklamator-youtube-your-blog
Show videos from youtube channel on your blog easily. Just paste one YouTube link and we will show widget with all your channel videos.
Embed Plus for YouTube Gallery, Livestream and Lazy Loading with Facades
youtube-embed-plus
A multi-featured plugin to embed YouTube in WordPress. Embed a video, YouTube channel gallery, playlist, or YouTube livestream. Defer JavaScript too!
Video Gallery – YouTube Playlist, Channel Gallery by YotuWP
yotuwp-easy-youtube-embed
Modern responsive YouTube video gallery helps your website getting noticed from visitors, increase the reach and stand out from the competitors.
Automatic YouTube Gallery
automatic-youtube-gallery
Build dynamic video galleries by simply adding a YouTube USERNAME, CHANNEL, PLAYLIST, SEARCH KEYWORDS, or a custom list of video URLs.
Feeds for YouTube (YouTube video, channel, and gallery plugin) Developer Profile
94 plugins · 23.5M total installs
How We Detect Feeds for YouTube (YouTube video, channel, and gallery plugin)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/feeds-for-youtube/admin/builder/css/layout.css/wp-content/plugins/feeds-for-youtube/admin/builder/css/style.css/wp-content/plugins/feeds-for-youtube/admin/css/sb-admin.css/wp-content/plugins/feeds-for-youtube/css/feed.css/wp-content/plugins/feeds-for-youtube/js/feed.js/wp-content/plugins/feeds-for-youtube/js/feed.jsfeeds-for-youtube/css/feed.css?ver=feeds-for-youtube/js/feed.js?ver=feeds-for-youtube/admin/css/sb-admin.css?ver=feeds-for-youtube/admin/builder/css/layout.css?ver=feeds-for-youtube/admin/builder/css/style.css?ver=HTML / DOM Fingerprints
sby_youtube_feedsby_feed_containersby_video_titlesby_channel_name<!-- Feeds for YouTube by Smash Balloon --><!-- Smash Balloon Customizer --><!-- /Smash Balloon Customizer -->data-sby-instancesby/wp-json/sby/v1/feed[youtube-feed[youtube-feed feed=1]