
(MB) YouTube Widget Security & Risk Analysis
wordpress.org/plugins/mb-youtube-videosThe YouTube videos widget lets you quickly and easily display your most recent YouTube videos in your blog's sidebar.
Is (MB) YouTube Widget Safe to Use in 2026?
Generally Safe
Score 85/100(MB) YouTube Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "mb-youtube-videos" v1.05 plugin exhibits a mixed security posture. While it has a small attack surface and a clean vulnerability history with no recorded CVEs, the static analysis reveals several concerning code practices. The presence of the `create_function` dangerous function is a significant red flag, as it can lead to arbitrary code execution vulnerabilities if not handled with extreme care, though its specific usage here is not detailed.
Furthermore, a substantial portion (84%) of the plugin's output is not properly escaped. This is a critical weakness that could allow for cross-site scripting (XSS) attacks, especially considering the lack of nonce checks and capability checks on its entry points. The single external HTTP request also warrants attention, as it could be a vector for SSRF or other network-related vulnerabilities if not properly validated and sanitized.
The lack of any recorded vulnerabilities in its history is positive, but it does not negate the inherent risks identified in the static analysis. The plugin demonstrates a reliance on good coding practices that are currently not being fully met, particularly around output sanitization. While the absence of known exploits is reassuring, the identified code signals suggest a potential for future vulnerabilities if not addressed.
Key Concerns
- Dangerous function create_function used
- Low percentage of properly escaped output
- No nonce checks on entry points
- No capability checks on entry points
(MB) YouTube Widget Security Vulnerabilities
(MB) YouTube Widget Code Analysis
Dangerous Functions Found
Output Escaping
(MB) YouTube Widget Attack Surface
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
(MB) YouTube Widget Maintenance & Trust
Maintenance Signals
Community Trust
(MB) YouTube Widget Alternatives
SocialFeeds
socialfeeds
YouTube feeds for WordPress with simple Setup and Settings options.
Social Counts – Youtube
social-counts-youtube
Social Counts - Youtube allows you to show the count of your youtube channel's subscribers.
Subscribe Button Bar for YouTube Embed Videos
subscribe-button-bar
A professional tool to add a YouTube subscribe button bar under your videos. Essential for channel growth and viewer conversion.
EmbedPress – PDF Embedder, Embed YouTube Videos, 3D FlipBook, Social feeds, Docs & more
embedpress
EmbedPress lets you embed videos, pages, social feeds, embed PDF 3D flipbooks & other content on WordPress without coding & enhance storytelling.
Feed Them Social – Social Media Feeds, Video, and Photo Galleries
feed-them-social
Custom social media feeds for Instagram, Facebook, TikTok, & YouTube. Works with Elementor, Beaver Builder, and Gutenberg blocks.
(MB) YouTube Widget Developer Profile
1 plugin · 70 total installs
How We Detect (MB) YouTube Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mb-youtube-videos/css/mechabyte-youtube.cssmechabyte-youtube.css?ver=HTML / DOM Fingerprints
mechabyte-youtube-videosmechabyte-display-decoratedmechabyte-display-plaintarget="_blank"<ul class="mechabyte-youtube-videos mechabyte-display-<li class="<img src="<div class="label"><h5>