
Lightweight and Responsive Youtube Embed Security & Risk Analysis
wordpress.org/plugins/lightweight-and-responsive-youtube-embedMake your embedded Youtube videos responsive & lightweight with this plugin. Reduce the loading time of your site and increase the user experience …
Is Lightweight and Responsive Youtube Embed Safe to Use in 2026?
High Risk
Score 43/100Lightweight and Responsive Youtube Embed carries significant security risk with 2 known CVEs, 2 still unpatched. Consider switching to a maintained alternative.
The plugin "lightweight-and-responsive-youtube-embed" v1.0.0 exhibits a mixed security posture. While it demonstrates good practices in areas like SQL query handling and avoiding file operations or external HTTP requests, significant concerns arise from its vulnerability history and output escaping. The static analysis shows no immediate critical code execution paths, dangerous functions, or unsanitized taint flows. However, the fact that 18% of outputs are not properly escaped, combined with a history of two unpatched medium-severity Cross-Site Scripting (XSS) vulnerabilities, strongly suggests a persistent weakness in input sanitization and output encoding. The lack of nonce and capability checks on the identified shortcode entry point, while currently unprotected by any other mechanism, further amplifies this risk.
The plugin's past vulnerabilities, particularly XSS, coupled with the current unescaped output, indicate a recurring problem with handling user-provided data safely. The recent unpatched vulnerabilities (dated 2025-04-01) are particularly concerning, as they represent known, exploitable flaws that could be leveraged by attackers. While the plugin has a small attack surface and no critical static code issues, the unpatched CVEs and the percentage of unescaped output are critical indicators of potential security risks that require immediate attention.
Key Concerns
- Two unpatched medium severity CVEs
- Significant percentage of unescaped output
- Lack of capability checks on shortcode
- Lack of nonce checks on shortcode
Lightweight and Responsive Youtube Embed Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Lightweight and Responsive Youtube Embed <= 1.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
Lightweight and Responsive Youtube Embed <= 1.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
Lightweight and Responsive Youtube Embed Code Analysis
Output Escaping
Lightweight and Responsive Youtube Embed Attack Surface
Shortcodes 1
WordPress Hooks 6
Maintenance & Trust
Lightweight and Responsive Youtube Embed Maintenance & Trust
Maintenance Signals
Community Trust
Lightweight and Responsive Youtube Embed Alternatives
Simple YouTube Embed
simple-youtube-embed
Embed YouTube videos in WordPress beautifully. Embed YouTube video with a URL or shortcode and customize the player using this YouTube embed plugin.
Responsive video embed
responsive-video-embed
Enables you three simple ways to embed responsive video into your content.
Shorts Video Embedder for YouTube
shorts-video-embedder-for-youtube
A plugin to embed and display YouTube Shorts from a channel via a shortcode.
YT Portrait Video Embed Block
yt-portrait-video-embed-block
A Gutenberg block for embedding portrait YouTube videos in posts or pages.
Responsive Video Embedder
responsive-video-embedder
A simple but powerful plugin to embed videos responsively into your Wordpress site. Works with both videos and playlists.
Lightweight and Responsive Youtube Embed Developer Profile
1 plugin · 40 total installs
How We Detect Lightweight and Responsive Youtube Embed
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/lightweight-and-responsive-youtube-embed/public/css/youtube-embed-style.css/wp-content/plugins/lightweight-and-responsive-youtube-embed/public/js/youtube-embed-script.js/wp-content/plugins/lightweight-and-responsive-youtube-embed/public/js/youtube-embed-script.jslightweight-and-responsive-youtube-embed/public/css/youtube-embed-style.css?ver=lightweight-and-responsive-youtube-embed/public/js/youtube-embed-script.js?ver=HTML / DOM Fingerprints
lyte-youtube-embeddata-youtube-id[youtube_embed url=