
ytSubscribe – Youtube Subscribe Button Security & Risk Analysis
wordpress.org/plugins/ytsubscribeAutomatically Add Youtube Subscribe Button Below each Video WordPress Plugin
Is ytSubscribe – Youtube Subscribe Button Safe to Use in 2026?
Generally Safe
Score 85/100ytSubscribe – Youtube Subscribe Button has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the provided static analysis and vulnerability history, the "ytsubscribe" plugin v2016.10.2.3 exhibits a generally strong security posture. The absence of any identified attack surface points, dangerous functions, raw SQL queries, file operations, external HTTP requests, and vulnerability history suggests a well-developed and secure plugin. The taint analysis also reported no critical or high severity flows, further bolstering confidence in its safety.
However, there are a few areas that warrant attention. The plugin has 0 nonces and 0 capability checks, which, combined with no recorded authentication checks on the identified entry points (though there are none), means that if any entry points were to be introduced in future updates or were somehow missed in this analysis, they would be unprotected. Furthermore, while 76% of output is properly escaped, the remaining 24% (approximately 4 out of 17 outputs) could potentially be vulnerable to cross-site scripting (XSS) if the data being output is user-controlled and not properly sanitized at the input stage. This is a minor concern given the overall clean bill of health, but it is a risk that should ideally be addressed.
In conclusion, this version of the "ytsubscribe" plugin appears to be very secure with no known vulnerabilities or exploitable code patterns detected. The lack of a significant attack surface is a major strength. The only areas for improvement are ensuring all output is properly escaped and that robust authentication and authorization mechanisms are in place if new entry points are ever added.
Key Concerns
- Unescaped output (24%)
- No nonce checks
- No capability checks
ytSubscribe – Youtube Subscribe Button Security Vulnerabilities
ytSubscribe – Youtube Subscribe Button Code Analysis
Output Escaping
ytSubscribe – Youtube Subscribe Button Attack Surface
WordPress Hooks 4
Maintenance & Trust
ytSubscribe – Youtube Subscribe Button Maintenance & Trust
Maintenance Signals
Community Trust
ytSubscribe – Youtube Subscribe Button Alternatives
Related Video Widget For Post From Youtube
tube-video-widget-using-post-meta
This plugin can show a related youtube video that you set in your post meta called "Youtube Video Link".
YouTube Video to WP Post
youtube-feed-2-wp-post
Import your YouTube Video as WordPress Post.
Video Gallery – YouTube Playlist, Channel Gallery by YotuWP
yotuwp-easy-youtube-embed
Modern responsive YouTube video gallery helps your website getting noticed from visitors, increase the reach and stand out from the competitors.
SocialFeeds
socialfeeds
YouTube feeds for WordPress with simple Setup and Settings options.
Video Gallery Block – Display your videos as a gallery in a professional way
video-gallery-block
Video Gallery Block lets you create responsive YouTube, Vimeo, and HTML5 video galleries with grid layouts, filters, and lightbox in Gutenberg.
ytSubscribe – Youtube Subscribe Button Developer Profile
2 plugins · 60 total installs
How We Detect ytSubscribe – Youtube Subscribe Button
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ytsubscribe/ytSubscribe.js/wp-content/plugins/ytsubscribe/ytSubscribe.jsytsubscribe/ytSubscribe.js?ver=2016.10.2.3HTML / DOM Fingerprints
ytSubscribe-innerytSubscribe-btndata-channeldata-themedata-countdata-layout<script>jQuery(document).ready(function($){ $('body').ytSubscribe({ button: { channel: '', theme: '', count: '', layout: '