Lightweight and Responsive Youtube Embed Security & Risk Analysis

wordpress.org/plugins/lightweight-and-responsive-youtube-embed

Make your embedded Youtube videos responsive & lightweight with this plugin. Reduce the loading time of your site and increase the user experience …

40 active installs v1.0.0 PHP + WP 3.0.0+ Updated Aug 27, 2018
embedlightweightresponsivevideoyoutube
43
D · High Risk
CVEs total2
Unpatched2
Last CVEApr 1, 2025
Download
Safety Verdict

Is Lightweight and Responsive Youtube Embed Safe to Use in 2026?

High Risk

Score 43/100

Lightweight and Responsive Youtube Embed carries significant security risk with 2 known CVEs, 2 still unpatched. Consider switching to a maintained alternative.

2 known CVEs 2 unpatched Last CVE: Apr 1, 2025Updated 7yr ago
Risk Assessment

The plugin "lightweight-and-responsive-youtube-embed" v1.0.0 exhibits a mixed security posture. While it demonstrates good practices in areas like SQL query handling and avoiding file operations or external HTTP requests, significant concerns arise from its vulnerability history and output escaping. The static analysis shows no immediate critical code execution paths, dangerous functions, or unsanitized taint flows. However, the fact that 18% of outputs are not properly escaped, combined with a history of two unpatched medium-severity Cross-Site Scripting (XSS) vulnerabilities, strongly suggests a persistent weakness in input sanitization and output encoding. The lack of nonce and capability checks on the identified shortcode entry point, while currently unprotected by any other mechanism, further amplifies this risk.

The plugin's past vulnerabilities, particularly XSS, coupled with the current unescaped output, indicate a recurring problem with handling user-provided data safely. The recent unpatched vulnerabilities (dated 2025-04-01) are particularly concerning, as they represent known, exploitable flaws that could be leveraged by attackers. While the plugin has a small attack surface and no critical static code issues, the unpatched CVEs and the percentage of unescaped output are critical indicators of potential security risks that require immediate attention.

Key Concerns

  • Two unpatched medium severity CVEs
  • Significant percentage of unescaped output
  • Lack of capability checks on shortcode
  • Lack of nonce checks on shortcode
Vulnerabilities
2

Lightweight and Responsive Youtube Embed Security Vulnerabilities

CVEs by Year

2 CVEs in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2025-31743medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Lightweight and Responsive Youtube Embed <= 1.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

Apr 1, 2025Unpatched
CVE-2025-31744medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Lightweight and Responsive Youtube Embed <= 1.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

Apr 1, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

Lightweight and Responsive Youtube Embed Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
9
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

18% escaped11 total outputs
Attack Surface

Lightweight and Responsive Youtube Embed Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[youtube_embed] public\class-wp-youtube-lightweight-embed-public.php:64
WordPress Hooks 6
actionadmin_menuadmin\class-wp-youtube-lightweight-embed-admin.php:54
actionadmin_initadmin\class-wp-youtube-lightweight-embed-admin.php:55
actionplugins_loadedincludes\class-wp-youtube-lightweight-embed.php:142
actionwp_enqueue_scriptsincludes\class-wp-youtube-lightweight-embed.php:169
actionwp_enqueue_scriptsincludes\class-wp-youtube-lightweight-embed.php:170
filterplugin_action_linkslightweight-and-responsive-youtube-embed.php:34
Maintenance & Trust

Lightweight and Responsive Youtube Embed Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedAug 27, 2018
PHP min version
Downloads2K

Community Trust

Rating60/100
Number of ratings2
Active installs40
Developer Profile

Lightweight and Responsive Youtube Embed Developer Profile

wpszaki

1 plugin · 40 total installs

54
trust score
Avg Security Score
43/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Lightweight and Responsive Youtube Embed

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/lightweight-and-responsive-youtube-embed/public/css/youtube-embed-style.css/wp-content/plugins/lightweight-and-responsive-youtube-embed/public/js/youtube-embed-script.js
Script Paths
/wp-content/plugins/lightweight-and-responsive-youtube-embed/public/js/youtube-embed-script.js
Version Parameters
lightweight-and-responsive-youtube-embed/public/css/youtube-embed-style.css?ver=lightweight-and-responsive-youtube-embed/public/js/youtube-embed-script.js?ver=

HTML / DOM Fingerprints

CSS Classes
lyte-youtube-embed
Data Attributes
data-youtube-id
Shortcode Output
[youtube_embed url=
FAQ

Frequently Asked Questions about Lightweight and Responsive Youtube Embed