Tiny YouTube Post Widget Security & Risk Analysis

wordpress.org/plugins/tiny-youtube-post-widget

This is a widget to display different YouTube videos in widget assigned for different posts or pages.

10 active installs v3.0.1 PHP + WP 3.0.1+ Updated Oct 8, 2016
meta-boxvideowidgetyoutube
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Tiny YouTube Post Widget Safe to Use in 2026?

Generally Safe

Score 85/100

Tiny YouTube Post Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The 'tiny-youtube-post-widget' plugin v3.0.1 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of known vulnerabilities and the plugin's avoidance of dangerous functions and raw SQL queries are positive indicators. Furthermore, the presence of nonce and capability checks, along with the use of prepared statements for SQL, demonstrate an understanding of secure coding practices. However, a significant concern arises from the low percentage of properly escaped output. With 28 total outputs and only 14% correctly escaped, there's a substantial risk of Cross-Site Scripting (XSS) vulnerabilities, particularly if any of these unsanitized outputs are directly rendered in the browser. While taint analysis showed no flows, this might be due to the limited scope of the analysis or the absence of complex data manipulation within the plugin, but it doesn't negate the risk identified by the output escaping issue.

Despite the lack of recorded CVEs and a clean vulnerability history, the identified output escaping issue represents a tangible risk that could be exploited. The plugin's minimal attack surface (two shortcodes) is a positive aspect, but the vulnerability in output handling could still be leveraged. The inclusion of Select2, a bundled library, warrants further investigation to ensure it's not an outdated or vulnerable version, though no specific data is provided to confirm this. In conclusion, while the plugin avoids many common pitfalls, the unaddressed output escaping is a critical weakness that needs immediate attention to mitigate potential XSS attacks.

Key Concerns

  • Low percentage of properly escaped output
  • Bundled Select2 library
Vulnerabilities
None known

Tiny YouTube Post Widget Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Tiny YouTube Post Widget Release Timeline

v1.0.0
Code Analysis
Analyzed Mar 16, 2026

Tiny YouTube Post Widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
24
4 escaped
Nonce Checks
1
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Select2

Output Escaping

14% escaped28 total outputs
Attack Surface

Tiny YouTube Post Widget Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[typw_tax] includes\class-tiny-youtube-post-widget.php:196
[typw_post] includes\class-tiny-youtube-post-widget.php:197
WordPress Hooks 11
actionadmin_initadmin\class-tiny-youtube-post-widget-admin.php:119
actionplugins_loadedincludes\class-tiny-youtube-post-widget.php:150
actionadmin_enqueue_scriptsincludes\class-tiny-youtube-post-widget.php:165
actionadmin_enqueue_scriptsincludes\class-tiny-youtube-post-widget.php:166
actionadmin_menuincludes\class-tiny-youtube-post-widget.php:168
actionadd_meta_boxesincludes\class-tiny-youtube-post-widget.php:170
actionsave_postincludes\class-tiny-youtube-post-widget.php:172
actionadmin_initincludes\class-tiny-youtube-post-widget.php:174
actionwp_enqueue_scriptsincludes\class-tiny-youtube-post-widget.php:191
actionwp_enqueue_scriptsincludes\class-tiny-youtube-post-widget.php:192
actionwidgets_initincludes\class-tiny-youtube-post-widget.php:194
Maintenance & Trust

Tiny YouTube Post Widget Maintenance & Trust

Maintenance Signals

WordPress version tested4.6.30
Last updatedOct 8, 2016
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings10
Active installs10
Developer Profile

Tiny YouTube Post Widget Developer Profile

Rnaby

4 plugins · 30 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Tiny YouTube Post Widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/tiny-youtube-post-widget/admin/css/select2.min.css/wp-content/plugins/tiny-youtube-post-widget/admin/css/tiny-youtube-post-widget-admin.css/wp-content/plugins/tiny-youtube-post-widget/admin/js/select2.full.min.js/wp-content/plugins/tiny-youtube-post-widget/admin/js/tiny-youtube-post-widget-admin.js
Version Parameters
tiny-youtube-post-widget/admin/css/tiny-youtube-post-widget-admin.css?ver=tiny-youtube-post-widget/admin/js/tiny-youtube-post-widget-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
sodathemes-typw-select2
HTML Comments
<!-- Tiny YouTube Post Widget URL -->
Data Attributes
rnaby_typw_inner_custom_box_nonce_rnaby_typw_meta_value_key
FAQ

Frequently Asked Questions about Tiny YouTube Post Widget