
WP YouTube Counters Security & Risk Analysis
wordpress.org/plugins/wp-youtube-countersAdds shortcodes to show YouTube channel's subscribers and video views count.
Is WP YouTube Counters Safe to Use in 2026?
Generally Safe
Score 85/100WP YouTube Counters has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-youtube-counters v0.2 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, the consistent use of prepared statements for all SQL queries, and the 100% proper output escaping are significant positive indicators. File operations and external HTTP requests are present but do not inherently signal risk without further context. The lack of taint analysis results with unsanitized paths is also reassuring.
However, there are notable areas of concern that detract from its overall security. The complete absence of nonce checks and capability checks, particularly for the identified shortcodes, represents a significant vulnerability. This means that any user, regardless of their WordPress role or privileges, could potentially trigger actions associated with these shortcodes, opening the door for Cross-Site Request Forgery (CSRF) attacks or unintended functionality execution if the shortcode logic is not inherently safe. The vulnerability history being entirely clean is a positive sign, but it does not mitigate the inherent risks introduced by the lack of proper authorization and anti-CSRF measures in the current code.
In conclusion, while the plugin demonstrates good practices in handling SQL and output, the lack of crucial security mechanisms like nonce and capability checks creates a substantial risk. The absence of known vulnerabilities in its history is a strength, but it's overshadowed by the potential for exploitation via its shortcode entry points. This plugin should not be deployed in a production environment without these critical security checks being implemented.
Key Concerns
- Missing nonce checks
- Missing capability checks
WP YouTube Counters Security Vulnerabilities
WP YouTube Counters Release Timeline
WP YouTube Counters Code Analysis
Output Escaping
WP YouTube Counters Attack Surface
Shortcodes 2
Maintenance & Trust
WP YouTube Counters Maintenance & Trust
Maintenance Signals
Community Trust
WP YouTube Counters Alternatives
List YouTube Channel Videos
list-youtube-channel-videos
Provide shortcode to show youtube videos of channel into website and play youtube videos directly from website. Use Shortcode [youtube-list-channel-vi …
Native YouTube Subscribe Button with Subscriber Counter
native-youtube-subscribe-button-with-subscriber-counter
Native YouTube Subscribe Button with Subscriber Counter plugin provide shortcode to place YouTube native style subscribe button in website with autoup …
YES! YouTube Essential Statistics
yes-youtube-essential-statistics-widget
A simple but robust Widgetized Heads up Display of any given YouTube Channel.
Post Views Counter
post-views-counter
Post Views Counter allows you to collect and display how many times a post, page, or other content has been viewed in a simple, fast and reliable way.
WP-PostViews
wp-postviews
Enables you to display how many times a post/page had been viewed.
WP YouTube Counters Developer Profile
2 plugins · 20 total installs
How We Detect WP YouTube Counters
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
[youtube_views_count][youtube_subscribers_count]