Video Youtube Lightbox Security & Risk Analysis

wordpress.org/plugins/video-youtube-lightbox

You can add your favorites Youtube videos in a playlist and display it in a responsive lightbox with a single click.

10 active installs v1.2.1 PHP + WP + Updated Aug 14, 2015
lightboxplaylistresponsivewidgetyoutube
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Video Youtube Lightbox Safe to Use in 2026?

Generally Safe

Score 85/100

Video Youtube Lightbox has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The plugin "video-youtube-lightbox" v1.2.1 demonstrates a strong security posture in several key areas. The static analysis reveals no dangerous functions, all SQL queries are properly prepared, and there are no indications of taint analysis issues, suggesting a low risk of common code injection vulnerabilities. The absence of known CVEs and a clean vulnerability history further reinforces this positive outlook, indicating a well-maintained and secure plugin. However, a significant concern arises from the low percentage of properly escaped output (12%). This suggests a potential risk of Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not sufficiently sanitized before being displayed on the frontend. While the plugin has capability checks in place, the lack of explicit nonce checks on AJAX handlers or proper permission callbacks for REST API routes (though these entry points are currently zero) could become a point of weakness if new entry points are introduced in future versions without adequate security measures.

Key Concerns

  • Low percentage of properly escaped output
  • No nonce checks on potential AJAX entry points
  • No permission callbacks on potential REST API entry points
Vulnerabilities
None known

Video Youtube Lightbox Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Video Youtube Lightbox Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
5 prepared
Unescaped Output
30
4 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared5 total queries

Output Escaping

12% escaped34 total outputs
Attack Surface

Video Youtube Lightbox Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionwidgets_initindex.php:277
actionwp_enqueue_scriptsindex.php:287
Maintenance & Trust

Video Youtube Lightbox Maintenance & Trust

Maintenance Signals

WordPress version tested4.2.39
Last updatedAug 14, 2015
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Video Youtube Lightbox Developer Profile

manudg

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Video Youtube Lightbox

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/video-youtube-lightbox/images/left.png/wp-content/plugins/video-youtube-lightbox/images/right.png
Script Paths
/wp-content/plugins/video-youtube-lightbox/js/main.js

HTML / DOM Fingerprints

CSS Classes
vyl-linkvyl-itemvyl-arrow-leftvyl-arrow-rightvyl-backvyl-box
Data Attributes
id="vyl-back"class="vyl-arrow-left"class="vyl-arrow-right"id="vyl-box"id="vyl-iframe"
JS Globals
jQuery
FAQ

Frequently Asked Questions about Video Youtube Lightbox