Plugin Name: My YouTube Videos Security & Risk Analysis

wordpress.org/plugins/my-youtube-videos

Displays your latest uploaded videos from your YouTube account on a full page or in your sidebar using the widget.

10 active installs v1.1 PHP + WP 2.7.0+ Updated Dec 9, 2010
hdplayliststhumbnailsvideosyoutube
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Plugin Name: My YouTube Videos Safe to Use in 2026?

Generally Safe

Score 85/100

Plugin Name: My YouTube Videos has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 15yr ago
Risk Assessment

The 'my-youtube-videos' v1.1 plugin exhibits a generally positive security posture based on the static analysis. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests is commendable. Furthermore, the lack of reported vulnerabilities in its history suggests a track record of secure development or timely patching. This indicates a relatively low risk of common attack vectors.

However, a significant concern lies in the output escaping. With only 12% of outputs properly escaped across 34 instances, there's a high likelihood of Cross-Site Scripting (XSS) vulnerabilities. This lack of robust output sanitization is a critical weakness that could allow attackers to inject malicious scripts into the site, potentially leading to session hijacking, defacement, or further exploitation. The absence of nonce checks and capability checks on the identified shortcode, while not immediately flagged as a vulnerability due to the limited attack surface, also presents a potential concern if the shortcode's functionality involves sensitive operations or user input that isn't sufficiently validated.

Key Concerns

  • Low percentage of properly escaped outputs
  • Missing nonce checks on shortcode
  • Missing capability checks on shortcode
Vulnerabilities
None known

Plugin Name: My YouTube Videos Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Plugin Name: My YouTube Videos Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
30
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

12% escaped34 total outputs
Attack Surface

Plugin Name: My YouTube Videos Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[my_youtube_videos] my_youtube_videos.php:49
WordPress Hooks 2
actionadmin_menumy_youtube_videos.php:79
actionwidgets_initmy_youtube_videos.php:292
Maintenance & Trust

Plugin Name: My YouTube Videos Maintenance & Trust

Maintenance Signals

WordPress version tested3.0.5
Last updatedDec 9, 2010
PHP min version
Downloads8K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Plugin Name: My YouTube Videos Developer Profile

Sébastien Dumont

15 plugins · 2K total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Plugin Name: My YouTube Videos

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/my-youtube-videos/my_youtube_videos.js
Script Paths
/wp-content/plugins/my-youtube-videos/my_youtube_videos.js

HTML / DOM Fingerprints

CSS Classes
latest_yt
HTML Comments
Runs when plugin is activatedRuns on plugin deactivationCreates new database fieldDeletes the database field+1 more
Data Attributes
data-myyt_usernamedata-myyt_display_manydata-myyt_display_thumbdata-myyt_display_dateaddeddata-myyt_enable_hd
JS Globals
my_youtube_videos
Shortcode Output
<table width="120px" cellpadding="2px" cellspacing="2px"><img class="latest_yt" src="http://i.ytimg.com/vi/YouTube Feed not found! Please try again later
FAQ

Frequently Asked Questions about Plugin Name: My YouTube Videos