GDPR-Extensions-com – Youtube 2xClick Solution Security & Risk Analysis

wordpress.org/plugins/gdpr-extensions-com-youtube-2clicksolution

Short Description: The GDPR YouTube 2xClick Solution lets you embed YouTube videos while protecting user privacy through consent-based loading.

0 active installs v1.0.1 PHP 8.1+ WP 6.4+ Updated Apr 25, 2025
embedgdprprivacyvideoyoutube
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is GDPR-Extensions-com – Youtube 2xClick Solution Safe to Use in 2026?

Generally Safe

Score 100/100

GDPR-Extensions-com – Youtube 2xClick Solution has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11mo ago
Risk Assessment

The "gdpr-extensions-com-youtube-2clicksolution" v1.0.1 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by using prepared statements for all SQL queries and escaping nearly all output, indicating a strong effort to prevent common injection and XSS vulnerabilities. The absence of known CVEs in its vulnerability history further suggests a relatively stable and well-maintained codebase, or at least one that hasn't had publicly disclosed vulnerabilities.

However, a significant concern arises from the attack surface. With 5 AJAX handlers identified, 3 of them lack authentication checks. This creates a direct pathway for unauthenticated users to interact with potentially sensitive backend functionality. While taint analysis did not reveal any unsanitized paths, the presence of unprotected AJAX endpoints significantly increases the risk of unauthorized actions or information disclosure if the functions they trigger are not inherently safe and self-validating.

In conclusion, the plugin has strengths in its handling of SQL and output escaping, and a clean vulnerability history. The primary weakness lies in the unprotected AJAX endpoints, which present a clear and exploitable risk that needs to be addressed to improve its overall security. The absence of critical taint flows and dangerous functions is a positive sign, but the unprotected entry points are a notable oversight.

Key Concerns

  • Unprotected AJAX handlers
Vulnerabilities
None known

GDPR-Extensions-com – Youtube 2xClick Solution Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

GDPR-Extensions-com – Youtube 2xClick Solution Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
9 prepared
Unescaped Output
1
27 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared9 total queries

Output Escaping

96% escaped28 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
gdprextensioncomyt_cookiewidget_save (functions\tabs_data.php:6)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
3 unprotected

GDPR-Extensions-com – Youtube 2xClick Solution Attack Surface

Entry Points5
Unprotected3

AJAX Handlers 5

authwp_ajax_gdprextensioncomyt_cookiewidget_savefunctions\tabs_data.php:132
noprivwp_ajax_gdprextensioncomyt_cookiewidget_savefunctions\tabs_data.php:133
authwp_ajax_gdprextensioncomyt_fetch_ytdataincludes\youtube-functions.php:91
noprivwp_ajax_gdprextensioncomyt_fetch_ytdataincludes\youtube-functions.php:92
authwp_ajax_gdprextensioncomyt_upload_imageviews\tab-setting-page.php:239
WordPress Hooks 9
actionwp_headgdpr-youtube.php:28
actioninitgdpr-youtube.php:29
filterblock_categories_allgdpr-youtube.php:30
actionwp_enqueue_scriptsgdpr-youtube.php:51
actionadmin_enqueue_scriptsgdpr-youtube.php:52
actionadmin_menugdpr-youtube.php:120
actionadmin_enqueue_scriptsgdpr-youtube.php:152
actionwp_enqueue_scriptsincludes\youtube-functions.php:55
actionadmin_enqueue_scriptsincludes\youtube-functions.php:81
Maintenance & Trust

GDPR-Extensions-com – Youtube 2xClick Solution Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedApr 25, 2025
PHP min version8.1
Downloads571

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

GDPR-Extensions-com – Youtube 2xClick Solution Developer Profile

GDPR-Extensions.com

3 plugins · 0 total installs

86
trust score
Avg Security Score
97/100
Avg Patch Time
37 days
View full developer profile
Detection Fingerprints

How We Detect GDPR-Extensions-com – Youtube 2xClick Solution

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gdpr-extensions-com-youtube-2clicksolution/assets/js/admin.js/wp-content/plugins/gdpr-extensions-com-youtube-2clicksolution/assets/js/min.js/wp-content/plugins/gdpr-extensions-com-youtube-2clicksolution/assets/css/admin.css/wp-content/plugins/gdpr-extensions-com-youtube-2clicksolution/assets/js/gdpr-youtube.js
Script Paths
assets/js/admin.jsassets/js/min.jsassets/js/gdpr-youtube.js
Version Parameters
gdpr-extensions-com-youtube-2clicksolution/assets/js/admin.js?ver=gdpr-extensions-com-youtube-2clicksolution/assets/js/min.js?ver=gdpr-extensions-com-youtube-2clicksolution/assets/css/admin.css?ver=gdpr-extensions-com-youtube-2clicksolution/assets/js/gdpr-youtube.js?ver=

HTML / DOM Fingerprints

CSS Classes
gdpr-youtube__wrapper
Data Attributes
data-blog-id
JS Globals
gdprextensioncomyt_blogidajax_object
FAQ

Frequently Asked Questions about GDPR-Extensions-com – Youtube 2xClick Solution