
YourChannel: Everything you want in a YouTube plugin. Security & Risk Analysis
wordpress.org/plugins/yourchannelSetup beautiful YouTube feed streams with 1 copy paste & 2 clicks. Displays banner, uploads, playlists and more (All optional).
Is YourChannel: Everything you want in a YouTube plugin. Safe to Use in 2026?
Generally Safe
Score 90/100YourChannel: Everything you want in a YouTube plugin. has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "yourchannel" plugin version 1.2.9 presents a significant security risk due to a large number of unprotected entry points. Specifically, 9 out of 10 identified entry points, including all AJAX handlers, lack authentication checks, making them vulnerable to unauthorized access and potential exploitation. The static analysis also reveals concerning trends in code security, with 0% of SQL queries using prepared statements and only 32% of output being properly escaped, increasing the risk of SQL injection and Cross-Site Scripting (XSS) vulnerabilities. Taint analysis indicates a high number of flows with unsanitized paths, further exacerbating these risks, although no critical or high severity taint issues were found in this specific analysis run.
The plugin's historical vulnerability data is a major red flag. With 9 known CVEs, including one high severity and eight medium severity, it demonstrates a pattern of past security weaknesses. While there are currently no unpatched CVEs, the frequency and types of past vulnerabilities (XSS, Missing Authorization, CSRF) strongly suggest that new, undiscovered vulnerabilities are likely to emerge. The last reported vulnerability was relatively recent, indicating ongoing security challenges. Despite the absence of dangerous functions and file operations, the combined risks from unprotected entry points, insecure SQL handling, poor output escaping, and a history of severe vulnerabilities make this plugin a high-risk component for any WordPress installation.
Key Concerns
- 9 unprotected AJAX handlers
- SQL queries without prepared statements
- Low percentage of properly escaped output
- High number of flows with unsanitized paths
- 1 high severity CVE history
- 8 medium severity CVE history
- Missing nonce check on 1 entry point
- Low percentage of capability checks
YourChannel: Everything you want in a YouTube plugin. Security Vulnerabilities
CVEs by Year
Severity Breakdown
9 total CVEs
YourChannel <= 1.2.5 - Authenticated (Administrator+) Stored Cross-Site Scripting
YourChannel <= 1.2.3 - Missing Authorization to Plugin Settings Reset
YourChannel <= 1.2.4 - Cross-Site Request Forgery to Plugin Channel Reset
YourChannel <= 1.2.4 - Cross-Site Request Forgery to Plugin Settings Change
YourChannel <= 1.2.3 - Missing Authorization to Plugin Cache Reset
YourChannel <= 1.2.4 - Cross-Site Request Forgery to Plugin Language Translation Update
YourChannel <= 1.2.4 - Cross-Site Request Forgery to Plugin Language Translation Reset
YourChannel <= 1.2.1 - Missing Authorization Checks leading to Authenticated (Subscriber+) Stored Cross-Site Scripting
YourChannel <= 1.2.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'yrc_lang[Videos]'
YourChannel: Everything you want in a YouTube plugin. Release Timeline
YourChannel: Everything you want in a YouTube plugin. Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
YourChannel: Everything you want in a YouTube plugin. Attack Surface
AJAX Handlers 9
Shortcodes 1
WordPress Hooks 9
Maintenance & Trust
YourChannel: Everything you want in a YouTube plugin. Maintenance & Trust
Maintenance Signals
Community Trust
YourChannel: Everything you want in a YouTube plugin. Alternatives
Curator Studio – YouTube – Show videos from channels, playlists and more
curator-studio-youtube
Curate YouTube content like never before.
Embed Plus for YouTube Gallery, Livestream and Lazy Loading with Facades
youtube-embed-plus
A multi-featured plugin to embed YouTube in WordPress. Embed a video, YouTube channel gallery, playlist, or YouTube livestream. Defer JavaScript too!
All-in-One Video Gallery
all-in-one-video-gallery
The ultimate video player & video gallery plugin for YouTubers, Video Bloggers, Course Creators, Podcasters, and anyone embedding videos on websites.
Feeds for YouTube (YouTube video, channel, and gallery plugin)
feeds-for-youtube
The Feeds for YouTube plugin allows you to display customizable YouTube feeds from any YouTube channel.
Video Gallery – YouTube Playlist, Channel Gallery by YotuWP
yotuwp-easy-youtube-embed
Modern responsive YouTube video gallery helps your website getting noticed from visitors, increase the reach and stand out from the competitors.
YourChannel: Everything you want in a YouTube plugin. Developer Profile
5 plugins · 10K total installs
How We Detect YourChannel: Everything you want in a YouTube plugin.
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/yourchannel/css/admin.css/wp-content/plugins/yourchannel/css/colorpicker/spectrum.css/wp-content/plugins/yourchannel/css/style.css/wp-content/plugins/yourchannel/js/admin.js/wp-content/plugins/yourchannel/js/yrc.js/wp-content/plugins/yourchannel/shortcode/shortcode.css/wp-content/plugins/yourchannel/shortcode/shortcode.js/wp-content/plugins/yourchannel/js/yrc.js/wp-content/plugins/yourchannel/js/admin.js/wp-content/plugins/yourchannel/shortcode/shortcode.jsyourchannel/js/yrc.js?ver=yourchannel/css/style.css?ver=yourchannel/shortcode/shortcode.css?v=yourchannel/js/admin.js?ver=yourchannel/css/colorpicker/spectrum.css?ver=yourchannel/js/colorpicker/spectrum.js?ver=yourchannel/shortcode/shortcode.js?ver=HTML / DOM Fingerprints
wpb-inlinepb-inlinedata-versionyrc_server_vars/wp-json/yourchannel/v1/[yourchannel