Jigoshop YouTube Video Product Tab Security & Risk Analysis

wordpress.org/plugins/jigoshop-youtube-video-product-tab

Extends Jigoshop to allow you to add a YouTube Video to the Product page. An additional tab is added on the single products page to allow your custome …

10 active installs v1.0 PHP + WP 3.3+ Updated Aug 25, 2014
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Jigoshop YouTube Video Product Tab Safe to Use in 2026?

Generally Safe

Score 85/100

Jigoshop YouTube Video Product Tab has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The plugin "jigoshop-youtube-video-product-tab" v1.0 appears to have a generally strong security posture based on the static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the potential attack surface. Furthermore, the fact that all detected SQL queries use prepared statements and there are no file operations or external HTTP requests are positive indicators of secure coding practices. The presence of at least one capability check is also encouraging.

However, the analysis does highlight some potential areas for concern. While the total number of outputs is moderate, a significant portion (39%) is not properly escaped. This could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is directly outputted without sufficient sanitization. The absence of nonce checks, while not directly linked to a large attack surface in this specific plugin, is a general security best practice that is missing and could be a concern in future iterations or if the attack surface expands.

Given the complete lack of known vulnerabilities (CVEs) and a clean taint analysis, the plugin has a historically good security record. This, combined with the limited attack surface and secure handling of database queries, suggests a well-maintained and relatively safe plugin. The primary risk lies in the unescaped output, which should be addressed to further strengthen its security. Overall, it's a promising plugin with a few areas that could be improved for maximum security.

Key Concerns

  • Output escaping is not properly handled for 39% of outputs
  • Nonce checks are completely missing
Vulnerabilities
None known

Jigoshop YouTube Video Product Tab Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Jigoshop YouTube Video Product Tab Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
28
44 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

61% escaped72 total outputs
Attack Surface

Jigoshop YouTube Video Product Tab Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 13
actionadmin_initjigoshop-youtube-video-product-tab.php:36
actioninitjigoshop-youtube-video-product-tab.php:67
actioninitjigoshop-youtube-video-product-tab.php:69
filterplugin_row_metajigoshop-youtube-video-product-tab.php:174
actionadmin_print_scriptsjigoshop-youtube-video-product-tab.php:175
actionadmin_enqueue_scriptsjigoshop-youtube-video-product-tab.php:176
actionjigoshop_product_tabsjigoshop-youtube-video-product-tab.php:178
actionjigoshop_product_tab_panelsjigoshop-youtube-video-product-tab.php:179
actionwp_enqueue_scriptsjigoshop-youtube-video-product-tab.php:182
actionjigoshop_product_write_panel_tabsjigoshop-youtube-video-product-tab.php:185
actionjigoshop_product_write_panelsjigoshop-youtube-video-product-tab.php:186
actionjigoshop_process_product_metajigoshop-youtube-video-product-tab.php:187
actionadmin_noticesjigoshop-youtube-video-product-tab.php:720
Maintenance & Trust

Jigoshop YouTube Video Product Tab Maintenance & Trust

Maintenance Signals

WordPress version tested3.5.2
Last updatedAug 25, 2014
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Alternatives

Jigoshop YouTube Video Product Tab Alternatives

No alternatives data available yet.

Developer Profile

Jigoshop YouTube Video Product Tab Developer Profile

Sébastien Dumont

15 plugins · 2K total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Jigoshop YouTube Video Product Tab

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Jigoshop YouTube Video Product Tab