YouTubeR by Maxio lab. Security & Risk Analysis

wordpress.org/plugins/mxyoutuber-responsive

The plugin allows you to upload your videos on YouTube from your website and embed YouTube videos to your website.

10 active installs v1.0.5 PHP + WP 4.3.0+ Updated Jul 30, 2016
apicachecachingembed-youtubeyoutube-videos
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is YouTubeR by Maxio lab. Safe to Use in 2026?

Generally Safe

Score 85/100

YouTubeR by Maxio lab. has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The mxyoutuber-responsive v1.0.5 plugin presents a mixed security posture. On the positive side, the plugin exhibits good practices in its handling of SQL queries, utilizing prepared statements exclusively, and shows no history of recorded vulnerabilities or CVEs. Furthermore, the static analysis found no dangerous functions, file operations, or external HTTP requests, contributing to a generally contained attack surface.

However, significant concerns arise from the output escaping and taint analysis. A complete lack of proper output escaping across all identified outputs is a critical weakness, potentially exposing the application to cross-site scripting (XSS) vulnerabilities. Additionally, the taint analysis revealed two flows with unsanitized paths, indicating that user-supplied data might be processed without adequate validation, even though no critical or high severity issues were flagged in this specific analysis. The absence of nonce checks and capability checks on the identified entry points, while not directly leading to immediate vulnerabilities based on the provided data, represents missed opportunities for robust security layering.

In conclusion, while the plugin has a clean vulnerability history and sound SQL practices, the pervasive lack of output escaping and the presence of unsanitized taint flows are substantial risks. These issues require immediate attention to prevent potential XSS and other injection-like attacks. The plugin's small attack surface is a mitigating factor, but the identified code-level weaknesses are serious.

Key Concerns

  • No proper output escaping detected
  • Taint analysis shows unsanitized paths
  • No nonce checks found
  • No capability checks found
Vulnerabilities
None known

YouTubeR by Maxio lab. Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

YouTubeR by Maxio lab. Release Timeline

v1.0.4
v1.0.3
v1.0.2
v1.0.1
v1.0
Code Analysis
Analyzed Mar 17, 2026

YouTubeR by Maxio lab. Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
20
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped20 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
mxYoutubeR_renderSettingsPage (functions.php:3)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

YouTubeR by Maxio lab. Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[mx_youtuber] mxyoutuber.php:21
WordPress Hooks 6
actionmedia_buttonsmxyoutuber.php:22
actionadmin_menumxyoutuber.php:23
actionwp_enqueue_scriptsmxyoutuber.php:31
actionadmin_enqueue_scriptsmxyoutuber.php:32
actionadmin_headmxyoutuber.php:33
actionplugins_loadedmxyoutuber.php:35
Maintenance & Trust

YouTubeR by Maxio lab. Maintenance & Trust

Maintenance Signals

WordPress version tested4.5.33
Last updatedJul 30, 2016
PHP min version
Downloads3K

Community Trust

Rating74/100
Number of ratings3
Active installs10
Developer Profile

YouTubeR by Maxio lab. Developer Profile

Maxio lab.

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect YouTubeR by Maxio lab.

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mxyoutuber-responsive/mxassets/css/frontend.css/wp-content/plugins/mxyoutuber-responsive/mxassets/js/frontend.js/wp-content/plugins/mxyoutuber-responsive/mxassets/lightcase/css/lightcase.css/wp-content/plugins/mxyoutuber-responsive/mxassets/lightcase/lightcase.js/wp-content/plugins/mxyoutuber-responsive/mxassets/css/backend.css/wp-content/plugins/mxyoutuber-responsive/mxassets/js/mxyoutube.js/wp-content/plugins/mxyoutuber-responsive/mxassets/js/media-uploader.js
Script Paths
https://apis.google.com/js/client.js
Version Parameters
mxyoutuber-responsive/mxassets/js/frontend.js?ver=mxyoutuber-responsive/mxassets/css/frontend.css?ver=mxyoutuber-responsive/mxassets/lightcase/lightcase.js?ver=mxyoutuber-responsive/mxassets/lightcase/css/lightcase.css?ver=mxyoutuber-responsive/mxassets/js/media-uploader.js?ver=mxyoutuber-responsive/mxassets/js/mxyoutube.js?ver=mxyoutuber-responsive/mxassets/css/backend.css?ver=

HTML / DOM Fingerprints

CSS Classes
wrapform-tableupdateddescription
Data Attributes
data-editordata-source
JS Globals
google
Shortcode Output
[mx_youtuber]
FAQ

Frequently Asked Questions about YouTubeR by Maxio lab.