
Tiny YouTube Post Widget Security & Risk Analysis
wordpress.org/plugins/tiny-youtube-post-widgetThis is a widget to display different YouTube videos in widget assigned for different posts or pages.
Is Tiny YouTube Post Widget Safe to Use in 2026?
Generally Safe
Score 85/100Tiny YouTube Post Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'tiny-youtube-post-widget' plugin v3.0.1 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of known vulnerabilities and the plugin's avoidance of dangerous functions and raw SQL queries are positive indicators. Furthermore, the presence of nonce and capability checks, along with the use of prepared statements for SQL, demonstrate an understanding of secure coding practices. However, a significant concern arises from the low percentage of properly escaped output. With 28 total outputs and only 14% correctly escaped, there's a substantial risk of Cross-Site Scripting (XSS) vulnerabilities, particularly if any of these unsanitized outputs are directly rendered in the browser. While taint analysis showed no flows, this might be due to the limited scope of the analysis or the absence of complex data manipulation within the plugin, but it doesn't negate the risk identified by the output escaping issue.
Despite the lack of recorded CVEs and a clean vulnerability history, the identified output escaping issue represents a tangible risk that could be exploited. The plugin's minimal attack surface (two shortcodes) is a positive aspect, but the vulnerability in output handling could still be leveraged. The inclusion of Select2, a bundled library, warrants further investigation to ensure it's not an outdated or vulnerable version, though no specific data is provided to confirm this. In conclusion, while the plugin avoids many common pitfalls, the unaddressed output escaping is a critical weakness that needs immediate attention to mitigate potential XSS attacks.
Key Concerns
- Low percentage of properly escaped output
- Bundled Select2 library
Tiny YouTube Post Widget Security Vulnerabilities
Tiny YouTube Post Widget Release Timeline
Tiny YouTube Post Widget Code Analysis
Bundled Libraries
Output Escaping
Tiny YouTube Post Widget Attack Surface
Shortcodes 2
WordPress Hooks 11
Maintenance & Trust
Tiny YouTube Post Widget Maintenance & Trust
Maintenance Signals
Community Trust
Tiny YouTube Post Widget Alternatives
Wonder Video Embed
wonderplugin-video-embed
Embed MP4, Youtube, Vimeo, Wistia videos to the sidebar widget, WordPress posts and pages.
My YouTube Channel
youtube-channel
Show video thumbnails or playable video block of recent YouTube Playlist, Channel (User Uploads) videos.
Auto Last Youtube Video
auto-last-youtube-video
This plugin provides both Widget and Shortcode to show latest videos from any public Youtube channel.
TechGasp Tube Master
youtube-master
TechGasp Tube Master displays Youtube Playlists or Single Videos with optional Youtube Subscribe Channel button and Google Hangouts.
Widgets for Youtube Video Feed
widgets-for-youtube-video-feed
Youtube Feed Widgets. Display your Youtube feed on your website to increase engagement, sales and SEO.
Tiny YouTube Post Widget Developer Profile
4 plugins · 30 total installs
How We Detect Tiny YouTube Post Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tiny-youtube-post-widget/admin/css/select2.min.css/wp-content/plugins/tiny-youtube-post-widget/admin/css/tiny-youtube-post-widget-admin.css/wp-content/plugins/tiny-youtube-post-widget/admin/js/select2.full.min.js/wp-content/plugins/tiny-youtube-post-widget/admin/js/tiny-youtube-post-widget-admin.jstiny-youtube-post-widget/admin/css/tiny-youtube-post-widget-admin.css?ver=tiny-youtube-post-widget/admin/js/tiny-youtube-post-widget-admin.js?ver=HTML / DOM Fingerprints
sodathemes-typw-select2<!-- Tiny YouTube Post Widget URL -->rnaby_typw_inner_custom_box_nonce_rnaby_typw_meta_value_key