jcwp youtube channel embed Security & Risk Analysis

wordpress.org/plugins/jcwp-youtube-channel-embed

This plugin embeds a custom channel to wordpress page or post

100 active installs v2.0.0 PHP + WP 2.8+ Updated Jun 4, 2015
channelcustom-channelcustom-youtube-channelembedyoutube
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is jcwp youtube channel embed Safe to Use in 2026?

Generally Safe

Score 85/100

jcwp youtube channel embed has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The "jcwp-youtube-channel-embed" v2.0.0 plugin exhibits a generally good security posture based on the provided static analysis. The absence of dangerous functions, raw SQL queries, file operations, external HTTP requests, and a lack of reported CVEs are all positive indicators. Furthermore, the limited attack surface with only one shortcode and no unprotected entry points is commendable.

However, there are a couple of areas for concern. The low percentage of properly escaped output (13%) is a significant weakness. This suggests that data displayed by the plugin might be susceptible to cross-site scripting (XSS) vulnerabilities if user-controlled input is not adequately sanitized before being rendered in the browser. The absence of nonce checks and capability checks on the identified entry points, although currently zero in number, means that if new entry points are added in the future without these security measures, the plugin could become vulnerable to unauthorized actions or data manipulation.

In conclusion, while the plugin demonstrates strengths in preventing common attack vectors like SQL injection and lacks a known vulnerability history, the poor output escaping practices represent a notable risk. The plugin should be reviewed for proper output sanitization to mitigate potential XSS vulnerabilities. The reliance on the absence of unprotected entry points as a security measure is precarious and could become a weakness if the plugin evolves without addressing the missing nonce and capability checks.

Key Concerns

  • Low output escaping percentage
  • Missing nonce checks on entry points
  • Missing capability checks on entry points
Vulnerabilities
None known

jcwp youtube channel embed Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

jcwp youtube channel embed Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
13
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

13% escaped15 total outputs
Attack Surface

jcwp youtube channel embed Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[jcorg_youtube_channel] jcwp-youtube-channel-embed.php:143
WordPress Hooks 5
actionadmin_menujcwp-youtube-channel-embed.php:42
actionadmin_enqueue_scriptsjcwp-youtube-channel-embed.php:47
actionadmin_initjcwp-youtube-channel-embed.php:51
actionwp_footerjcwp-youtube-channel-embed.php:74
actionwp_headjcwp-youtube-channel-embed.php:85
Maintenance & Trust

jcwp youtube channel embed Maintenance & Trust

Maintenance Signals

WordPress version tested4.2.39
Last updatedJun 4, 2015
PHP min version
Downloads15K

Community Trust

Rating76/100
Number of ratings4
Active installs100
Developer Profile

jcwp youtube channel embed Developer Profile

Jaspreet Chahal

7 plugins · 560 total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect jcwp youtube channel embed

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/jcwp-youtube-channel-embed/css/prettyPhoto.css/wp-content/plugins/jcwp-youtube-channel-embed/css/jcYoutubeChannelEmbedd.css/wp-content/plugins/jcwp-youtube-channel-embed/jquery.prettyPhoto.js/wp-content/plugins/jcwp-youtube-channel-embed/jcorgYoutubeUserChannelEmbed.js
Script Paths
/wp-content/plugins/jcwp-youtube-channel-embed/jcorgYoutubeUserChannelEmbed.js

HTML / DOM Fingerprints

CSS Classes
jcorgbsuccessjcorgber
Data Attributes
data-reldata-animationdata-bgfixeddata-bgpositiondata-bgrepeatdata-bgscroll+32 more
JS Globals
jcorgYoutubeUserChannelEmbed
Shortcode Output
<div id=''></div><div style='clear:both !important'>&nbsp;</div><script type="text/javascript">jQuery(document).ready(function(){
FAQ

Frequently Asked Questions about jcwp youtube channel embed