YouTube Video to WP Post Security & Risk Analysis

wordpress.org/plugins/youtube-feed-2-wp-post

Import your YouTube Video as WordPress Post.

10 active installs v1.5 PHP + WP 3.8+ Updated May 1, 2016
appzcoderpostsohelaminyoutubeyoutube-video
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is YouTube Video to WP Post Safe to Use in 2026?

Generally Safe

Score 85/100

YouTube Video to WP Post has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The "youtube-feed-2-wp-post" plugin v1.5 exhibits a mixed security posture. On the positive side, it has no known historical vulnerabilities (CVEs) and does not appear to bundle outdated libraries. The static analysis also shows no critical or high severity taint flows and a limited number of external requests. However, several concerning practices are evident in the code analysis. The presence of one AJAX handler without authentication checks presents a significant attack vector. Furthermore, the plugin uses raw SQL queries without prepared statements, which is a common vulnerability source. The low percentage of properly escaped output is also a red flag, as it indicates a high risk of cross-site scripting (XSS) vulnerabilities. While the absence of historical vulnerabilities is a good sign, the current code analysis reveals potential weaknesses that could be exploited if not addressed.

Key Concerns

  • AJAX handler without auth checks
  • SQL queries without prepared statements
  • Low percentage of properly escaped output
  • No capability checks
Vulnerabilities
None known

YouTube Video to WP Post Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

YouTube Video to WP Post Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
11
2 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

15% escaped13 total outputs
Attack Surface
1 unprotected

YouTube Video to WP Post Attack Surface

Entry Points2
Unprotected1

AJAX Handlers 1

authwp_ajax_yt2wp_importyoutube-video-to-wp-post.php:112

Shortcodes 1

[yt2wp_show_youtube_video] youtube-video-to-wp-post.php:110
WordPress Hooks 12
actionadmin_menuincludes\class-admin-menu.php:18
actionadmin_initincludes\class-admin-menu.php:19
actioninityoutube-video-to-wp-post.php:30
actionadmin_enqueue_scriptsyoutube-video-to-wp-post.php:90
actionadmin_footeryoutube-video-to-wp-post.php:91
actionyt2wp_youtube_video_importyoutube-video-to-wp-post.php:93
actionadd_meta_boxesyoutube-video-to-wp-post.php:95
actionsave_postyoutube-video-to-wp-post.php:99
filtercron_schedulesyoutube-video-to-wp-post.php:115
actionupdate_option_yt2wp_auto_importyoutube-video-to-wp-post.php:120
actionupdate_option_yt2wp_cron_job_scheduleyoutube-video-to-wp-post.php:121
actionupdate_option_yt2wp_youtube_user_idyoutube-video-to-wp-post.php:122

Scheduled Events 1

yt2wp_youtube_video_import
Maintenance & Trust

YouTube Video to WP Post Maintenance & Trust

Maintenance Signals

WordPress version tested4.5.33
Last updatedMay 1, 2016
PHP min version
Downloads5K

Community Trust

Rating90/100
Number of ratings4
Active installs10
Developer Profile

YouTube Video to WP Post Developer Profile

sohelamin

3 plugins · 30 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect YouTube Video to WP Post

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/youtube-feed-2-wp-post/assets/css/style.css

HTML / DOM Fingerprints

CSS Classes
import-loader
Data Attributes
name="youtube_user_id"name="post_category"id="yt2wp_post_youtube_video_id"id="yt2wp_import_form"
JS Globals
ajaxurlyt2wp_enqueue_js
Shortcode Output
[yt2wp_show_youtube_video]
FAQ

Frequently Asked Questions about YouTube Video to WP Post