
WP YouTube Player Security & Risk Analysis
wordpress.org/plugins/wp-youtube-playerInsert Youtube Videos on WordPress blog.
Is WP YouTube Player Safe to Use in 2026?
Generally Safe
Score 85/100WP YouTube Player has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-youtube-player v1.7 plugin exhibits a strong security posture in several key areas. The static analysis reveals a complete absence of exposed entry points like AJAX handlers, REST API routes, and shortcodes without authentication checks. Furthermore, all SQL queries are performed using prepared statements, and there are no dangerous functions identified in the code. The plugin also demonstrates good practice with a single nonce check present. However, a significant concern arises from the complete lack of output escaping across all identified output points. This means any data rendered by the plugin could potentially be injected with malicious scripts, leading to Cross-Site Scripting (XSS) vulnerabilities. The vulnerability history is clean, with no recorded CVEs, which is a positive indicator of the plugin's past security. Despite the lack of direct vulnerabilities in its history, the unescaped output represents a notable weakness that could be exploited. Overall, while the plugin has a solid foundation regarding attack surface and data handling, the lack of output sanitization is a critical oversight that requires immediate attention.
Key Concerns
- Output escaping is not properly implemented
WP YouTube Player Security Vulnerabilities
WP YouTube Player Code Analysis
Output Escaping
Data Flow Analysis
WP YouTube Player Attack Surface
WordPress Hooks 4
Maintenance & Trust
WP YouTube Player Maintenance & Trust
Maintenance Signals
Community Trust
WP YouTube Player Alternatives
Player with Playlist Block for WordPress Editor
video-playlist-lite
Simply add single youtube videos, youtube playlists or create youtube playlists on your WordPress blog.
A.R.M.Y. VideoSlider Plugin – Insert Online Videos Using Shortcodes
army-video-slider
The A.R.M.Y. VideoSlider Plugin allows you to easily add a video slider to your WordPress site,
iframe
iframe
[iframe src="http://www.youtube.com/embed/7_nAZQt9qu0" width="100%" height="500"] shortcode
Video Gallery – YouTube Playlist, Channel Gallery by YotuWP
yotuwp-easy-youtube-embed
Modern responsive YouTube video gallery helps your website getting noticed from visitors, increase the reach and stand out from the competitors.
Simple YouTube Embed
simple-youtube-embed
Embed YouTube videos in WordPress beautifully. Embed YouTube video with a URL or shortcode and customize the player using this YouTube embed plugin.
WP YouTube Player Developer Profile
4 plugins · 2K total installs
How We Detect WP YouTube Player
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-youtube-player/tubeplayer.swfwp-youtube-player/style.css?ver=wp-youtube-player/js/script.js?ver=HTML / DOM Fingerprints
<!-- For more information, visit: http://blog.unijimpe.net/wp-youtube-player/ -->data-iddata-widthdata-heightdata-autoplaydata-showinfodata-theme+7 morewindow.WP_TUBE_SETTINGS[tube][/tube]