WP Youtube Gallery Security & Risk Analysis

wordpress.org/plugins/wp-youtube-gallery

WP YouTube Gallery is a simple and lightweight WP plugin that allows you to add a YouTube video gallery to any page or post using a shortcode.

400 active installs v2.0 PHP + WP 6.0+ Updated Jan 4, 2025
galleryvideo-gallerywp-video-galleryyoutube-gallery
91
A · Safe
CVEs total1
Unpatched0
Last CVEJan 6, 2025
Safety Verdict

Is WP Youtube Gallery Safe to Use in 2026?

Generally Safe

Score 91/100

WP Youtube Gallery has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Jan 6, 2025Updated 1yr ago
Risk Assessment

The plugin 'wp-youtube-gallery' v2.0 demonstrates a generally strong security posture based on the provided static analysis. The absence of dangerous functions, use of prepared statements for all SQL queries, and 100% proper output escaping are commendable practices. The presence of nonce and capability checks on all identified entry points (two shortcodes) further enhances its security. There are no identified taint flows of critical or high severity, and no currently unpatched CVEs.

However, the plugin's vulnerability history, which includes one known CVE in the past, albeit patched, suggests a past susceptibility to Cross-Site Scripting (XSS) vulnerabilities. While the current version appears to have addressed this, a history of XSS, even if resolved, warrants continued vigilance. The limited attack surface and lack of external HTTP requests are positive indicators, but the past occurrence of a common vulnerability type should not be entirely disregarded when considering long-term security. Overall, the current version appears secure, but a cautious approach due to past vulnerability patterns is advised.

Key Concerns

  • Past known CVE in history
Vulnerabilities
1 published

WP Youtube Gallery Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-12590medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

WP Youtube Gallery <= 1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter

Jan 6, 2025 Patched in 2.0 (24d)
Version History

WP Youtube Gallery Release Timeline

v2.0Current
v1.91 CVE
v1.81 CVE
v1.71 CVE
v1.61 CVE
v1.51 CVE
v1.41 CVE
v1.31 CVE
v1.21 CVE
v1.11 CVE
v1.01 CVE
Code Analysis
Analyzed Mar 16, 2026

WP Youtube Gallery Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
45 escaped
Nonce Checks
1
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped45 total outputs
Attack Surface

WP Youtube Gallery Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[wp_youtube_gallery] wpyg-class.php:308
[wyg] wpyg-class.php:309
WordPress Hooks 11
actionadmin_initwp-youtube-gallery.php:24
actionadmin_menuwp-youtube-gallery.php:25
actionadmin_bar_menuwp-youtube-gallery.php:31
filtermanage_edit-wp_youtube_gallery_taxonomy_columnswp-youtube-gallery.php:32
filtermanage_wp_youtube_gallery_taxonomy_custom_columnwp-youtube-gallery.php:33
actionadmin_footerwp-youtube-gallery.php:279
actioninitwpyg-class.php:11
actionadd_meta_boxeswpyg-class.php:42
actionsave_postwpyg-class.php:135
actioninitwpyg-class.php:189
actionwp_enqueue_scriptswpyg-class.php:223
Maintenance & Trust

WP Youtube Gallery Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedJan 4, 2025
PHP min version
Downloads20K

Community Trust

Rating80/100
Number of ratings6
Active installs400
Developer Profile

WP Youtube Gallery Developer Profile

WP-EXPERTS.IN

21 plugins · 30K total installs

72
trust score
Avg Security Score
90/100
Avg Patch Time
347 days
View full developer profile
Detection Fingerprints

How We Detect WP Youtube Gallery

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-youtube-gallery/js/wpyg_gallery.js/wp-content/plugins/wp-youtube-gallery/css/wpyg_gallery.css/wp-content/plugins/wp-youtube-gallery/css/wpyg_gallery.css?ver=1.0/wp-content/plugins/wp-youtube-gallery/js/wpyg_gallery.js?ver=1.0

HTML / DOM Fingerprints

CSS Classes
wpyg-toolbar-pagewpyg_menu_item_classwpyg-tab-linkswpyg-settingwpyg-tab
Data Attributes
wpyg_titlewpyg_descwpyg_iframe_wwpyg_min_hwpyg_content_limit
JS Globals
wpyg_gallery
Shortcode Output
[wyg slug=[wp_youtube_gallery category_slug=
FAQ

Frequently Asked Questions about WP Youtube Gallery