
YouTube DJ Security & Risk Analysis
wordpress.org/plugins/youtube-djBe a DJ with the YouTube DJ Gear.
Is YouTube DJ Safe to Use in 2026?
Generally Safe
Score 85/100YouTube DJ has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "youtube-dj" plugin v0.4 exhibits a mixed security posture. While it demonstrates good practices such as using prepared statements for all SQL queries and a high percentage of properly escaped output, significant concerns arise from its unprotected entry points. Specifically, the presence of two AJAX handlers without any authentication or capability checks creates a considerable attack surface. This means any unauthenticated user could potentially trigger these functions, leading to unintended consequences or information disclosure if the functions themselves perform sensitive actions or handle data insecurely. The taint analysis, while showing no critical or high severity flows, did reveal two flows with unsanitized paths, which could become exploitable if combined with other vulnerabilities or if the functions they originate from are triggered by malicious input. The plugin's vulnerability history is currently clean, with no recorded CVEs. This is a positive indicator, suggesting a historical focus on security or simply a lack of discovered vulnerabilities to date. However, this does not negate the risks identified in the static analysis. The key strengths are the secure SQL handling and output escaping, but the unprotected AJAX handlers represent a critical weakness that needs immediate attention.
Key Concerns
- AJAX handlers without auth checks
- Taint flow with unsanitized path
- Taint flow with unsanitized path
- Missing nonce checks on AJAX
- Missing capability checks on AJAX
YouTube DJ Security Vulnerabilities
YouTube DJ Code Analysis
Output Escaping
Data Flow Analysis
YouTube DJ Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
YouTube DJ Maintenance & Trust
Maintenance Signals
Community Trust
YouTube DJ Alternatives
EmbedPress – PDF Embedder, Embed YouTube Videos, 3D FlipBook, Social feeds, Docs & more
embedpress
EmbedPress lets you embed videos, pages, social feeds, embed PDF 3D flipbooks & other content on WordPress without coding & enhance storytelling.
Feeds for YouTube (YouTube video, channel, and gallery plugin)
feeds-for-youtube
The Feeds for YouTube plugin allows you to display customizable YouTube feeds from any YouTube channel.
The Ultimate Video Player For WordPress – by Presto Player
presto-player
The Ultimate WordPress Video Player.
Embed Plus for YouTube Gallery, Livestream and Lazy Loading with Facades
youtube-embed-plus
A multi-featured plugin to embed YouTube in WordPress. Embed a video, YouTube channel gallery, playlist, or YouTube livestream. Defer JavaScript too!
iframe
iframe
[iframe src="http://www.youtube.com/embed/7_nAZQt9qu0" width="100%" height="500"] shortcode
YouTube DJ Developer Profile
9 plugins · 870 total installs
How We Detect YouTube DJ
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/youtube-dj/css/style.css/wp-content/plugins/youtube-dj/css/ui-lightness/jquery-ui-1.7.2.custom.css/wp-content/plugins/youtube-dj/js/ytdj.jsjs/ytdj.jsyoutubedj/js/ytdj.js?ver=youtubedj/css/style.css?ver=youtubedj/css/ui-lightness/jquery-ui-1.7.2.custom.css?ver=HTML / DOM Fingerprints
boothrack-leftrackrack-rightrack-centerdata-dismiss="modal"youtubedj<div class="booth"><div class="rack-left rack"><div class="rack-right rack"><div class="rack-center rack">