WP Youtube channel gallery Security & Risk Analysis

wordpress.org/plugins/wp-youtube-channel-gallery

Displays the most recent videos on a YouTube channel in your wp blog.

100 active installs v2.1 PHP + WP 2.1+ Updated Jul 12, 2011
channellistaryoutubeyoutube-galleryyt
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP Youtube channel gallery Safe to Use in 2026?

Generally Safe

Score 85/100

WP Youtube channel gallery has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 14yr ago
Risk Assessment

The "wp-youtube-channel-gallery" v2.1 plugin demonstrates a generally good security posture based on the provided static analysis. A key strength is the complete absence of SQL queries that do not use prepared statements and no identified dangerous functions. The plugin also reports zero known CVEs, indicating a history of responsible maintenance or a lack of past exploitable vulnerabilities. However, there are notable areas of concern. A significant weakness is the low percentage (52%) of properly escaped output, which leaves the plugin susceptible to Cross-Site Scripting (XSS) vulnerabilities. Furthermore, the complete lack of nonce checks and capability checks, especially given the presence of a shortcode (an entry point), is a serious oversight that could allow unauthorized actions or privilege escalation if the shortcode handler is not inherently secure. The absence of taint analysis results is also a neutral observation, as it doesn't confirm security but rather a lack of data or a very limited attack surface for taint analysis in this specific scan.

Key Concerns

  • Low output escaping percentage
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

WP Youtube channel gallery Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WP Youtube channel gallery Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
13
14 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

52% escaped27 total outputs
Attack Surface

WP Youtube channel gallery Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[youtubechannel] wp-youtube-list-channel.php:42
WordPress Hooks 1
actionwidgets_initwp-youtube-list-channel.php:39
Maintenance & Trust

WP Youtube channel gallery Maintenance & Trust

Maintenance Signals

WordPress version tested3.0.5
Last updatedJul 12, 2011
PHP min version
Downloads30K

Community Trust

Rating60/100
Number of ratings2
Active installs100
Developer Profile

WP Youtube channel gallery Developer Profile

brunoneves

2 plugins · 110 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP Youtube channel gallery

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
wp_youtube_gallerywp_youtube_widget
HTML Comments
The wp_youtube_gallery_post_page() JavaScript function places the YouTube video code here
Data Attributes
channelnamenumvideoswidthshowvideotitletitleshowtitle
Shortcode Output
<div class="wp_youtube_gallery"><object width='' height=''><param name='movie' value='
FAQ

Frequently Asked Questions about WP Youtube channel gallery