Video Lightbox for YouTube/Vimeo Security & Risk Analysis

wordpress.org/plugins/youtubefancybox

Embed YouTube/Vimeo videos in a lightbox popup. Easily create thumbnails and customize playback settings. Supports both platforms and is compatible wi …

100 active installs v2.7.1 PHP 8.1+ WP 5.6+ Updated Oct 15, 2024
lightboxpopup-videoshortcodevimeoyoutube
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Video Lightbox for YouTube/Vimeo Safe to Use in 2026?

Generally Safe

Score 92/100

Video Lightbox for YouTube/Vimeo has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The youtubefancybox plugin v2.7.1 exhibits a strong security posture based on the provided static analysis. The plugin demonstrates excellent adherence to secure coding practices, with no dangerous functions identified, all SQL queries utilizing prepared statements, and all output properly escaped. The absence of file operations and external HTTP requests further minimizes potential attack vectors. Notably, the plugin also includes capability checks, indicating an awareness of access control. The taint analysis shows no identified flows with unsanitized paths, reinforcing the lack of critical or high-severity vulnerabilities in this area.

The plugin's vulnerability history is also clean, with no recorded CVEs of any severity. This pattern of no past vulnerabilities, combined with the strong static analysis results, suggests a well-maintained and secure codebase. The plugin's attack surface is minimal, with zero identified entry points, which is an ideal scenario for security. While the absence of nonce checks on AJAX handlers or REST API routes might seem like a weakness, given that there are no such handlers or routes, it does not present a direct risk in this specific version.

In conclusion, the youtubefancybox plugin v2.7.1 appears to be a highly secure option based on this analysis. Its strengths lie in its robust implementation of secure coding standards and its clean vulnerability history. The only potential area for future consideration would be the explicit inclusion of nonce checks and permission callbacks if the plugin were to introduce any new AJAX or REST API endpoints in future versions, but for the current state, this is not a concern.

Vulnerabilities
None known

Video Lightbox for YouTube/Vimeo Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Video Lightbox for YouTube/Vimeo Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
8 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped8 total outputs
Attack Surface

Video Lightbox for YouTube/Vimeo Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionadmin_menuyoutubefancybox.php:45
actionadmin_enqueue_scriptsyoutubefancybox.php:46
actionwp_enqueue_scriptsyoutubefancybox.php:51
filterwidget_textyoutubefancybox.php:52
filterwidget_textyoutubefancybox.php:53
actionplugins_loadedyoutubefancybox.php:54
Maintenance & Trust

Video Lightbox for YouTube/Vimeo Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedOct 15, 2024
PHP min version8.1
Downloads12K

Community Trust

Rating66/100
Number of ratings7
Active installs100
Developer Profile

Video Lightbox for YouTube/Vimeo Developer Profile

Milind More

1 plugin · 100 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Video Lightbox for YouTube/Vimeo

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/youtubefancybox/css/youtubefancybox-amp.css/wp-content/plugins/youtubefancybox/css/colorbox.css/wp-content/plugins/youtubefancybox/js/jquery.colorbox.js/wp-content/plugins/youtubefancybox/js/caller.js/wp-content/plugins/youtubefancybox/js/fancybox_admin.js
Script Paths
js/fancybox_admin.jsjs/jquery.colorbox.jsjs/caller.js
Version Parameters
youtubefancybox/css/youtubefancybox-amp.css?ver=youtubefancybox/css/colorbox.css?ver=youtubefancybox/js/jquery.colorbox.js?ver=youtubefancybox/js/caller.js?ver=youtubefancybox/js/fancybox_admin.js?ver=

HTML / DOM Fingerprints

JS Globals
fancybox_admin_obj
FAQ

Frequently Asked Questions about Video Lightbox for YouTube/Vimeo