
Jigoshop YouTube Video Product Tab Security & Risk Analysis
wordpress.org/plugins/jigoshop-youtube-video-product-tabExtends Jigoshop to allow you to add a YouTube Video to the Product page. An additional tab is added on the single products page to allow your custome …
Is Jigoshop YouTube Video Product Tab Safe to Use in 2026?
Generally Safe
Score 85/100Jigoshop YouTube Video Product Tab has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "jigoshop-youtube-video-product-tab" v1.0 appears to have a generally strong security posture based on the static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the potential attack surface. Furthermore, the fact that all detected SQL queries use prepared statements and there are no file operations or external HTTP requests are positive indicators of secure coding practices. The presence of at least one capability check is also encouraging.
However, the analysis does highlight some potential areas for concern. While the total number of outputs is moderate, a significant portion (39%) is not properly escaped. This could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is directly outputted without sufficient sanitization. The absence of nonce checks, while not directly linked to a large attack surface in this specific plugin, is a general security best practice that is missing and could be a concern in future iterations or if the attack surface expands.
Given the complete lack of known vulnerabilities (CVEs) and a clean taint analysis, the plugin has a historically good security record. This, combined with the limited attack surface and secure handling of database queries, suggests a well-maintained and relatively safe plugin. The primary risk lies in the unescaped output, which should be addressed to further strengthen its security. Overall, it's a promising plugin with a few areas that could be improved for maximum security.
Key Concerns
- Output escaping is not properly handled for 39% of outputs
- Nonce checks are completely missing
Jigoshop YouTube Video Product Tab Security Vulnerabilities
Jigoshop YouTube Video Product Tab Code Analysis
Output Escaping
Jigoshop YouTube Video Product Tab Attack Surface
WordPress Hooks 13
Maintenance & Trust
Jigoshop YouTube Video Product Tab Maintenance & Trust
Maintenance Signals
Community Trust
Jigoshop YouTube Video Product Tab Alternatives
No alternatives data available yet.
Jigoshop YouTube Video Product Tab Developer Profile
15 plugins · 2K total installs
How We Detect Jigoshop YouTube Video Product Tab
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.