Native YouTube Subscribe Button with Subscriber Counter Security & Risk Analysis

wordpress.org/plugins/native-youtube-subscribe-button-with-subscriber-counter

Native YouTube Subscribe Button with Subscriber Counter plugin provide shortcode to place YouTube native style subscribe button in website with autoup …

10 active installs v1.0 PHP + WP 4.7+ Updated Jan 30, 2018
subscribesubscribe-button-shortcodesubscribers-counteryoutubeyoutube-subscribe-button
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Native YouTube Subscribe Button with Subscriber Counter Safe to Use in 2026?

Generally Safe

Score 85/100

Native YouTube Subscribe Button with Subscriber Counter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The static analysis of the "native-youtube-subscribe-button-with-subscriber-counter" plugin v1.0 reveals a generally good security posture. The plugin effectively utilizes prepared statements for its SQL queries, ensures all identified outputs are properly escaped, and has no external HTTP requests or file operations that could be exploited. The absence of known CVEs and historical vulnerabilities further strengthens this positive outlook, suggesting a development team that is either proactive in addressing security or has not yet encountered any significant issues. However, there are areas for improvement. The lack of nonce checks and capability checks for the identified shortcode is a notable concern, as it represents a potential entry point for unauthorized actions if not properly handled within the shortcode's functionality. While the total attack surface is small, any unprotected entry point warrants attention.

Despite the positive indicators, the absence of nonce and capability checks on the shortcode is the primary area of concern. If the shortcode performs any sensitive actions or modifies data, it could be vulnerable to Cross-Site Request Forgery (CSRF) attacks or unauthorized content manipulation. The taint analysis also shows zero flows, which is excellent, but this could be due to the limited complexity or scope of the plugin's code. The overall conclusion is that the plugin is reasonably secure, but the lack of authorization checks on its sole entry point is a weakness that should be addressed to further enhance its security.

Key Concerns

  • Missing nonce check on shortcode
  • Missing capability check on shortcode
Vulnerabilities
None known

Native YouTube Subscribe Button with Subscriber Counter Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Native YouTube Subscribe Button with Subscriber Counter Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped1 total outputs
Attack Surface

Native YouTube Subscribe Button with Subscriber Counter Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[nysb-youtube-btn] plugin.php:32
Maintenance & Trust

Native YouTube Subscribe Button with Subscriber Counter Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedJan 30, 2018
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Native YouTube Subscribe Button with Subscriber Counter Developer Profile

Girdhari Choyal

4 plugins · 30 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Native YouTube Subscribe Button with Subscriber Counter

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/native-youtube-subscribe-button-with-subscriber-counter/nysb-script.js/wp-content/plugins/native-youtube-subscribe-button-with-subscriber-counter/nysb-style.css
Script Paths
/wp-content/plugins/native-youtube-subscribe-button-with-subscriber-counter/nysb-script.js
Version Parameters
native-youtube-subscribe-button-with-subscriber-counter/nysb-script.js?ver=native-youtube-subscribe-button-with-subscriber-counter/nysb-style.css?ver=

HTML / DOM Fingerprints

CSS Classes
nysb-youtube-subscribe-buttonyoutube-sub-count
Shortcode Output
<a class="nysb-youtube-subscribe-button"<span class="youtube-sub-count">
FAQ

Frequently Asked Questions about Native YouTube Subscribe Button with Subscriber Counter