
Strx Youtube Embed Widget Security & Risk Analysis
wordpress.org/plugins/strx-youtube-widgetStrx Youtube Embed Widget lets you embed youtube videos on sidebars enabled sites simply pasting Youtube URLs
Is Strx Youtube Embed Widget Safe to Use in 2026?
Generally Safe
Score 85/100Strx Youtube Embed Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The strx-youtube-widget v1.1.2 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices regarding SQL queries, exclusively using prepared statements, and has no recorded vulnerability history, suggesting a history of secure development. It also reports zero entry points exposed via AJAX, REST API, shortcodes, or cron events, and no identified taint flows, which significantly reduces its attack surface.
However, several concerning signals emerge from the static analysis. The presence of the `create_function` is a significant risk as it is deprecated and can be a vector for code injection if not handled with extreme care, though no specific exploit is evident in the current analysis. Furthermore, a substantial portion of output (71%) is not properly escaped, posing a risk of Cross-Site Scripting (XSS) vulnerabilities. The absence of nonce and capability checks on any potential entry points, if they were to exist, also represents a security weakness. While the plugin currently has no known CVEs, the identified code signals warrant attention for future development and auditing.
Key Concerns
- Dangerous function 'create_function' used
- Significant portion of output not escaped
- No nonce checks found
- No capability checks found
Strx Youtube Embed Widget Security Vulnerabilities
Strx Youtube Embed Widget Code Analysis
Dangerous Functions Found
Output Escaping
Strx Youtube Embed Widget Attack Surface
WordPress Hooks 1
Maintenance & Trust
Strx Youtube Embed Widget Maintenance & Trust
Maintenance Signals
Community Trust
Strx Youtube Embed Widget Alternatives
SM YouTube Video iFrame
sm-youtube-video-iframe
The pluging for embed youtube video using youtube video id.
iframe
iframe
[iframe src="http://www.youtube.com/embed/7_nAZQt9qu0" width="100%" height="500"] shortcode
Widget Responsive for Youtube
youtube-widget-responsive
Widgets + ShortCode responsive to embed youtube in your sidebar or in your content [youtube video=...] or in WPBakery Page Builder, with SEO http://sc …
Simple YouTube Embed
simple-youtube-embed
Embed YouTube videos in WordPress beautifully. Embed YouTube video with a URL or shortcode and customize the player using this YouTube embed plugin.
Wonder Video Embed
wonderplugin-video-embed
Embed MP4, Youtube, Vimeo, Wistia videos to the sidebar widget, WordPress posts and pages.
Strx Youtube Embed Widget Developer Profile
4 plugins · 120 total installs
How We Detect Strx Youtube Embed Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/strx-youtube-widget/strx-youtube-widget.js/wp-content/plugins/strx-youtube-widget/strx-youtube-widget.css/wp-content/plugins/strx-youtube-widget/strx-youtube-widget.jsstrx-youtube-widget/strx-youtube-widget.js?ver=strx-youtube-widget/strx-youtube-widget.css?ver=HTML / DOM Fingerprints
strx-youtube-embed