
TubEntertain Security & Risk Analysis
wordpress.org/plugins/tubentertainTubEntertain Is a Powerful wordpress Plugin That Let You Create a Video Gallery of Your YouTube Videos and Live Stream in your WordPress or Other We …
Is TubEntertain Safe to Use in 2026?
Generally Safe
Score 85/100TubEntertain has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'tubentertain' v2.0 plugin exhibits a concerning security posture due to significant weaknesses in input validation and authentication. The static analysis reveals two AJAX handlers that lack authentication checks, presenting a direct attack surface for potential unauthorized actions. Furthermore, the plugin's output escaping is notably poor, with only 25% of outputs being properly escaped, increasing the risk of cross-site scripting (XSS) vulnerabilities. The taint analysis, while not reporting critical or high severity flows, does indicate three flows with unsanitized paths, which, combined with the unescaped outputs, could lead to exploitable vulnerabilities. The complete absence of nonce and capability checks on critical entry points like AJAX handlers further exacerbates these risks. Despite a clean vulnerability history, this does not guarantee future security, and the current code analysis suggests a reactive rather than proactive security approach. The plugin's strengths lie in its minimal use of dangerous functions and the majority of its SQL queries utilizing prepared statements, but these are overshadowed by the identified weaknesses in authentication and output sanitization.
Key Concerns
- AJAX handlers without auth checks
- Low percentage of properly escaped output
- Taint flows with unsanitized paths
- Missing nonce checks
- Missing capability checks
TubEntertain Security Vulnerabilities
TubEntertain Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
TubEntertain Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 9
Maintenance & Trust
TubEntertain Maintenance & Trust
Maintenance Signals
Community Trust
TubEntertain Alternatives
Embed Videos For Product Image Gallery Using WooCommerce
woocommerce-embed-videos-to-product-image-gallery
Embed videos to product gallery along with images on product page of WooCommerce.
Faster YouTube Embed
faster-youtube-embed
Faster YouTube Embed enables you to insert YouTube videos to any page and post quickly and efficiently & you’ll have no hassle of slow YouTube vid …
Rio Video Gallery
rio-video-gallery
A powerful Video Gallery plugin that allows you to embed videos from YouTube, Vimeo and Dailymotion through categories. You can manage them through a …
skiv video embedding
muse-ai
This plugin enables skiv.com oEmbed links, and adds shortcodes to easily embed videos hosted on skiv.com.
Feeds for YouTube (YouTube video, channel, and gallery plugin)
feeds-for-youtube
The Feeds for YouTube plugin allows you to display customizable YouTube feeds from any YouTube channel.
TubEntertain Developer Profile
1 plugin · 10 total installs
How We Detect TubEntertain
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
tubentertain/style.css?ver=tubentertain/js/main.js?ver=HTML / DOM Fingerprints
tubentertain-wrappertubentertain-playertubentertain-controlstubentertain-playlist-itemdata-tubentertain-channeldata-tubentertain-playlist-iddata-tubentertain-video-iddata-tubentertain-api-keytubentertain_playertubentertain_playlist[tubentertain