Jawda YouTube Embed Security & Risk Analysis

wordpress.org/plugins/jawda-youtube-embed

A very easy wordpress plugin for add shortcode to Embed a responsive SEO Friendly YouTube video

0 active installs v0.1 PHP 7.0.0+ WP 4.0+ Updated Nov 10, 2021
embedschemaseo-friendlyvideosyoutube
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Jawda YouTube Embed Safe to Use in 2026?

Generally Safe

Score 85/100

Jawda YouTube Embed has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The "jawda-youtube-embed" v0.1 plugin exhibits a generally good security posture from a static analysis perspective. The absence of dangerous functions, SQL queries without prepared statements, file operations, external HTTP requests, and a low number of entry points (only one shortcode) are positive indicators. The taint analysis showing zero flows with unsanitized paths further contributes to this positive outlook, suggesting that the core functionalities are likely not susceptible to injection-based attacks based on this analysis.

However, the plugin's security is not without potential concerns. The most notable weakness is the complete lack of nonce checks and capability checks. This means that the shortcode, which represents the sole entry point, could potentially be triggered by unauthenticated users or users without the necessary permissions, depending on how it's implemented. While the static analysis didn't identify direct vulnerabilities in the shortcode's processing, this lack of access control is a significant security gap that could be exploited if the shortcode's functionality were to be misused or if it interacted with sensitive data.

The plugin's vulnerability history is also a strong point, with zero recorded CVEs. This suggests a history of stable and likely secure development. Overall, the "jawda-youtube-embed" v0.1 plugin demonstrates good coding practices in several key areas, but the absence of proper authentication and authorization mechanisms for its shortcode is a critical oversight that significantly increases its risk profile.

Key Concerns

  • No nonce checks on entry points
  • No capability checks on entry points
  • Output escaping not fully implemented
Vulnerabilities
None known

Jawda YouTube Embed Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Jawda YouTube Embed Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
9 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

75% escaped12 total outputs
Attack Surface

Jawda YouTube Embed Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[jawda_yt] yt.php:75
WordPress Hooks 5
filtermce_external_pluginsjawda-youtube-embed.php:31
filtermce_buttonsjawda-youtube-embed.php:32
actionadmin_headjawda-youtube-embed.php:37
actionenqueue_block_editor_assetsjawda-youtube-embed.php:80
filterblock_categoriesjawda-youtube-embed.php:101
Maintenance & Trust

Jawda YouTube Embed Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedNov 10, 2021
PHP min version7.0.0
Downloads7K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Jawda YouTube Embed Developer Profile

Sabry Suleiman

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Jawda YouTube Embed

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/jawda-youtube-embed/js/classic_editor.js/wp-content/plugins/jawda-youtube-embed/js/gutenberg_block.js

HTML / DOM Fingerprints

CSS Classes
center
Data Attributes
data-urldata-title
Shortcode Output
[jawda_yt]<iframe<script type="application/ld+json">
FAQ

Frequently Asked Questions about Jawda YouTube Embed