
YES! YouTube Essential Statistics Security & Risk Analysis
wordpress.org/plugins/yes-youtube-essential-statistics-widgetA simple but robust Widgetized Heads up Display of any given YouTube Channel.
Is YES! YouTube Essential Statistics Safe to Use in 2026?
Generally Safe
Score 85/100YES! YouTube Essential Statistics has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "yes-youtube-essential-statistics-widget" plugin, version 1.0.0, presents a mixed security profile. On one hand, the absence of known CVEs and a complete lack of SQL injection vulnerabilities through prepared statements are positive indicators. The plugin also boasts a very small attack surface with no identifiable AJAX handlers, REST API routes, shortcodes, or cron events, and zero external HTTP requests or file operations, which reduces the opportunities for certain types of attacks.
However, significant concerns arise from the static analysis. The use of the deprecated `create_function` is a critical security anti-pattern that can lead to remote code execution if misused. Furthermore, the fact that 100% of the 13 output operations are not properly escaped represents a high risk of Cross-Site Scripting (XSS) vulnerabilities. This means that data outputted by the plugin could potentially contain malicious scripts that are then executed by a user's browser. The absence of any nonce checks or capability checks on potential entry points (even though the attack surface is currently zero) also means that if new entry points were introduced or existing ones were discovered, they would be unprotected.
In conclusion, while the plugin has a clean vulnerability history and no known exploitable flaws in its current state, the identified code quality issues, particularly the unescaped output and the use of `create_function`, introduce significant potential security weaknesses. These issues require immediate attention to secure the plugin against potential XSS and RCE attacks, especially if the plugin's functionality were to expand.
Key Concerns
- Use of deprecated create_function
- 100% of outputs not properly escaped
- 0 Nonce checks on potential entry points
- 0 Capability checks on potential entry points
YES! YouTube Essential Statistics Security Vulnerabilities
YES! YouTube Essential Statistics Release Timeline
YES! YouTube Essential Statistics Code Analysis
Dangerous Functions Found
Output Escaping
YES! YouTube Essential Statistics Attack Surface
WordPress Hooks 1
Maintenance & Trust
YES! YouTube Essential Statistics Maintenance & Trust
Maintenance Signals
Community Trust
YES! YouTube Essential Statistics Alternatives
WP YouTube Counters
wp-youtube-counters
Adds shortcodes to show YouTube channel's subscribers and video views count.
YouTube Subscribe widget
youtube-subscribe-widget
Add a widget to display YouTube subscribe box in the sidebar.
Video Reviews / Video Widget
video-reviews
Transform your website with engaging video content. Add a powerful Video Reviews widget to your footer and boost conversions instantly.
Show Twitter Followers
show-twitter-followers
Show Twitter Followers does what its name says-display your twitter followers in the sidebar as a widget.
List YouTube Channel Videos
list-youtube-channel-videos
Provide shortcode to show youtube videos of channel into website and play youtube videos directly from website. Use Shortcode [youtube-list-channel-vi …
YES! YouTube Essential Statistics Developer Profile
1 plugin · 10 total installs
How We Detect YES! YouTube Essential Statistics
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
youtube_essential_widgetid="youtube_essential_widget"name="youtube_essential_widget"