YourChannel: Everything you want in a YouTube plugin. Security & Risk Analysis

wordpress.org/plugins/yourchannel

Setup beautiful YouTube feed streams with 1 copy paste & 2 clicks. Displays banner, uploads, playlists and more (All optional).

10K active installs v1.2.9 PHP + WP 3.5+ Updated Aug 23, 2024
streamyoutubeyoutube-galleryyoutube-playeryoutube-playlists
90
A · Safe
CVEs total9
Unpatched0
Last CVEApr 18, 2023
Safety Verdict

Is YourChannel: Everything you want in a YouTube plugin. Safe to Use in 2026?

Generally Safe

Score 90/100

YourChannel: Everything you want in a YouTube plugin. has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

9 known CVEsLast CVE: Apr 18, 2023Updated 1yr ago
Risk Assessment

The "yourchannel" plugin version 1.2.9 presents a significant security risk due to a large number of unprotected entry points. Specifically, 9 out of 10 identified entry points, including all AJAX handlers, lack authentication checks, making them vulnerable to unauthorized access and potential exploitation. The static analysis also reveals concerning trends in code security, with 0% of SQL queries using prepared statements and only 32% of output being properly escaped, increasing the risk of SQL injection and Cross-Site Scripting (XSS) vulnerabilities. Taint analysis indicates a high number of flows with unsanitized paths, further exacerbating these risks, although no critical or high severity taint issues were found in this specific analysis run.

The plugin's historical vulnerability data is a major red flag. With 9 known CVEs, including one high severity and eight medium severity, it demonstrates a pattern of past security weaknesses. While there are currently no unpatched CVEs, the frequency and types of past vulnerabilities (XSS, Missing Authorization, CSRF) strongly suggest that new, undiscovered vulnerabilities are likely to emerge. The last reported vulnerability was relatively recent, indicating ongoing security challenges. Despite the absence of dangerous functions and file operations, the combined risks from unprotected entry points, insecure SQL handling, poor output escaping, and a history of severe vulnerabilities make this plugin a high-risk component for any WordPress installation.

Key Concerns

  • 9 unprotected AJAX handlers
  • SQL queries without prepared statements
  • Low percentage of properly escaped output
  • High number of flows with unsanitized paths
  • 1 high severity CVE history
  • 8 medium severity CVE history
  • Missing nonce check on 1 entry point
  • Low percentage of capability checks
Vulnerabilities
9 published

YourChannel: Everything you want in a YouTube plugin. Security Vulnerabilities

CVEs by Year

9 CVEs in 2023
2023
Patched Has unpatched

Severity Breakdown

High
1
Medium
8

9 total CVEs

CVE-2023-1869medium · 5.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

YourChannel <= 1.2.5 - Authenticated (Administrator+) Stored Cross-Site Scripting

Apr 18, 2023 Patched in 1.2.6 (280d)
CVE-2023-1865medium · 6.5Missing Authorization

YourChannel <= 1.2.3 - Missing Authorization to Plugin Settings Reset

Apr 5, 2023 Patched in 1.2.4 (293d)
CVE-2023-1866medium · 5.4Cross-Site Request Forgery (CSRF)

YourChannel <= 1.2.4 - Cross-Site Request Forgery to Plugin Channel Reset

Apr 5, 2023 Patched in 1.2.5 (293d)
CVE-2023-1867medium · 5.4Cross-Site Request Forgery (CSRF)

YourChannel <= 1.2.4 - Cross-Site Request Forgery to Plugin Settings Change

Apr 5, 2023 Patched in 1.2.5 (293d)
CVE-2023-1868medium · 6.5Missing Authorization

YourChannel <= 1.2.3 - Missing Authorization to Plugin Cache Reset

Apr 5, 2023 Patched in 1.2.4 (293d)
CVE-2023-1870medium · 4.3Cross-Site Request Forgery (CSRF)

YourChannel <= 1.2.4 - Cross-Site Request Forgery to Plugin Language Translation Update

Apr 5, 2023 Patched in 1.2.5 (293d)
CVE-2023-1871medium · 5.4Cross-Site Request Forgery (CSRF)

YourChannel <= 1.2.4 - Cross-Site Request Forgery to Plugin Language Translation Reset

Apr 5, 2023 Patched in 1.2.5 (293d)
CVE-2022-4833high · 7.4Missing Authorization

YourChannel <= 1.2.1 - Missing Authorization Checks leading to Authenticated (Subscriber+) Stored Cross-Site Scripting

Jan 13, 2023 Patched in 1.2.2 (375d)
CVE-2023-0282medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

YourChannel <= 1.2.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'yrc_lang[Videos]'

Jan 13, 2023 Patched in 1.2.2 (375d)
Version History

YourChannel: Everything you want in a YouTube plugin. Release Timeline

Code Analysis
Analyzed Mar 16, 2026

YourChannel: Everything you want in a YouTube plugin. Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
13
6 escaped
Nonce Checks
1
Capability Checks
2
File Operations
0
External Requests
3
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

32% escaped19 total outputs
Data Flows · Security
4 unsanitized

Data Flow Analysis

5 flows4 with unsanitized paths
delete (YourChannel.php:479)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
9 unprotected

YourChannel: Everything you want in a YouTube plugin. Attack Surface

Entry Points10
Unprotected9

AJAX Handlers 9

authwp_ajax_yrc_saveYourChannel.php:62
authwp_ajax_yrc_getYourChannel.php:63
authwp_ajax_yrc_deleteYourChannel.php:64
authwp_ajax_yrc_get_langYourChannel.php:65
authwp_ajax_yrc_save_langYourChannel.php:66
authwp_ajax_yrc_delete_langYourChannel.php:67
authwp_ajax_yrc_clear_keysYourChannel.php:68
authwp_ajax_yrc_clear_cacheYourChannel.php:69
authwp_ajax_yrc_upgrade_nag_dismissYourChannel.php:645

Shortcodes 1

[yourchannel] YourChannel.php:74
WordPress Hooks 9
actionadmin_menuYourChannel.php:54
actionadmin_initYourChannel.php:55
actionplugins_loadedYourChannel.php:56
actionadmin_enqueue_scriptsYourChannel.php:58
actionwp_enqueue_scriptsYourChannel.php:59
actionwp_footerYourChannel.php:60
actionmedia_buttonsYourChannel.php:71
actionprint_media_templatesYourChannel.php:72
actionadmin_noticesYourChannel.php:644
Maintenance & Trust

YourChannel: Everything you want in a YouTube plugin. Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedAug 23, 2024
PHP min version
Downloads465K

Community Trust

Rating92/100
Number of ratings80
Active installs10K
Developer Profile

YourChannel: Everything you want in a YouTube plugin. Developer Profile

plugin.builders

5 plugins · 10K total installs

69
trust score
Avg Security Score
86/100
Avg Patch Time
279 days
View full developer profile
Detection Fingerprints

How We Detect YourChannel: Everything you want in a YouTube plugin.

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/yourchannel/css/admin.css/wp-content/plugins/yourchannel/css/colorpicker/spectrum.css/wp-content/plugins/yourchannel/css/style.css/wp-content/plugins/yourchannel/js/admin.js/wp-content/plugins/yourchannel/js/yrc.js/wp-content/plugins/yourchannel/shortcode/shortcode.css/wp-content/plugins/yourchannel/shortcode/shortcode.js
Script Paths
/wp-content/plugins/yourchannel/js/yrc.js/wp-content/plugins/yourchannel/js/admin.js/wp-content/plugins/yourchannel/shortcode/shortcode.js
Version Parameters
yourchannel/js/yrc.js?ver=yourchannel/css/style.css?ver=yourchannel/shortcode/shortcode.css?v=yourchannel/js/admin.js?ver=yourchannel/css/colorpicker/spectrum.css?ver=yourchannel/js/colorpicker/spectrum.js?ver=yourchannel/shortcode/shortcode.js?ver=

HTML / DOM Fingerprints

CSS Classes
wpb-inlinepb-inline
Data Attributes
data-version
JS Globals
yrc_server_vars
REST Endpoints
/wp-json/yourchannel/v1/
Shortcode Output
[yourchannel
FAQ

Frequently Asked Questions about YourChannel: Everything you want in a YouTube plugin.