
Video Gallery – YouTube Gallery & Responsive Video Playlist Security & Risk Analysis
wordpress.org/plugins/youtube-showcaseResponsive video gallery and YouTube gallery for WordPress. Create a video grid or YouTube playlist visually in the block editor. No shortcodes!
Is Video Gallery – YouTube Gallery & Responsive Video Playlist Safe to Use in 2026?
Generally Safe
Score 96/100Video Gallery – YouTube Gallery & Responsive Video Playlist has a strong security track record. Known vulnerabilities have been patched promptly.
The 'youtube-showcase' v4.0.2 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for all SQL queries, making it resilient to traditional SQL injection attacks. Additionally, a high percentage of output is properly escaped, reducing the risk of cross-site scripting (XSS) vulnerabilities in the rendered content. The plugin also incorporates nonce and capability checks for most of its entry points.
However, significant concerns arise from the static analysis. The plugin exposes 9 AJAX handlers without any authentication checks, presenting a substantial attack surface for unauthorized actions. The taint analysis revealed 2 critical severity flows and 9 flows with unsanitized paths, indicating potential vulnerabilities that could be exploited if malicious data is introduced. While there are no currently unpatched CVEs, the historical vulnerability data shows a pattern of past issues including Deserialization of Untrusted Data, Missing Authorization, and Cross-Site Request Forgery (CSRF), suggesting a recurring tendency towards authorization and data handling weaknesses.
In conclusion, while the plugin has strengths in its database and output handling, the numerous unprotected AJAX endpoints and identified taint flow issues are serious risks that need immediate attention. The historical vulnerability data further underscores the need for rigorous security reviews and remediation efforts. The plugin's security is compromised by its unprotected entry points and the presence of critical taint flows.
Key Concerns
- 9 AJAX handlers without auth checks
- 2 critical severity taint flows
- 9 flows with unsanitized paths
- 1 high severity known CVE
- 2 medium severity known CVEs
- Bundled outdated library: Select2 v3.2
- 16% of outputs not properly escaped
Video Gallery – YouTube Gallery & Responsive Video Playlist Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
YouTube Showcase <= 3.5.1 - Unauthenticated PHP Object Injection
YouTube Video Gallery by YouTube Showcase – Video Gallery Plugin for WordPress <= 3.3.6 - Missing Authorization to Arbitrary Post/Page Creation
Video Gallery & Management <= 3.3.5 - Cross-Site Request Forgery
Video Gallery – YouTube Gallery & Responsive Video Playlist Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Video Gallery – YouTube Gallery & Responsive Video Playlist Attack Surface
AJAX Handlers 29
Shortcodes 5
WordPress Hooks 89
Maintenance & Trust
Video Gallery – YouTube Gallery & Responsive Video Playlist Maintenance & Trust
Maintenance Signals
Community Trust
Video Gallery – YouTube Gallery & Responsive Video Playlist Alternatives
Video Gallery – YouTube Playlist, Channel Gallery by YotuWP
yotuwp-easy-youtube-embed
Modern responsive YouTube video gallery helps your website getting noticed from visitors, increase the reach and stand out from the competitors.
Automatic YouTube Gallery
automatic-youtube-gallery
Build dynamic video galleries by simply adding a YouTube USERNAME, CHANNEL, PLAYLIST, SEARCH KEYWORDS, or a custom list of video URLs.
FancyTube – Video Gallery, Video Slider, and Playlist Slider for YouTube
video-gallery-playlist
Create stunning YouTube video galleries, sliders, and playlists. Perfect for bloggers, vloggers, and businesses.
GS YouTube Gallery – Video Feed, Channel Playlist & YouTube Slider
gs-youtube-gallery
Create a Stunning & Responsive Video Gallery for Channel or Playlist Videos.
Feeds for YouTube (YouTube video, channel, and gallery plugin)
feeds-for-youtube
The Feeds for YouTube plugin allows you to display customizable YouTube feeds from any YouTube channel.
Video Gallery – YouTube Gallery & Responsive Video Playlist Developer Profile
10 plugins · 4K total installs
How We Detect Video Gallery – YouTube Gallery & Responsive Video Playlist
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/youtube-showcase/assets/css/emd-video-list.css/wp-content/plugins/youtube-showcase/assets/css/emd-video-single.css/wp-content/plugins/youtube-showcase/assets/css/responsive-video.css/wp-content/plugins/youtube-showcase/assets/js/emd-video-helpers.js/wp-content/plugins/youtube-showcase/assets/js/emd-video-list.js/wp-content/plugins/youtube-showcase/assets/js/emd-video-single.js/wp-content/plugins/youtube-showcase/assets/js/jquery.fitvids.js/wp-content/plugins/youtube-showcase/assets/js/emd-video-helpers.js/wp-content/plugins/youtube-showcase/assets/js/emd-video-list.js/wp-content/plugins/youtube-showcase/assets/js/emd-video-single.js/wp-content/plugins/youtube-showcase/assets/js/jquery.fitvids.js/wp-content/plugins/youtube-showcase/assets/css/emd-video-list.css?ver=/wp-content/plugins/youtube-showcase/assets/css/emd-video-single.css?ver=/wp-content/plugins/youtube-showcase/assets/css/responsive-video.css?ver=/wp-content/plugins/youtube-showcase/assets/js/emd-video-helpers.js?ver=/wp-content/plugins/youtube-showcase/assets/js/emd-video-list.js?ver=/wp-content/plugins/youtube-showcase/assets/js/emd-video-single.js?ver=/wp-content/plugins/youtube-showcase/assets/js/jquery.fitvids.js?ver=HTML / DOM Fingerprints
emd-video-listemd-single-video-wrapperemd-video-player-wrapperYoutube Showcase - Video Galleryemd_video_gallerydata-emd-video-listdata-emd-video-iddata-video-autoplaydata-video-reldata-video-controlsdata-video-showinfo+3 moreemd_video_globalemd_video_players/wp-json/youtube-showcase/v1/videos/wp-json/youtube-showcase/v1/settings[emd_video_gallery[emd_single_video