A blank YouTube area in WordPress can mean the embed was never created, a consent tool intentionally withheld it, or YouTube rejected playback. Identify which state you have before replacing the player or disabling the consent system.
Start With One Public Test Page
Record the video URL, page URL, editor block, browser, and consent state. Open the video directly on YouTube and check whether it is accessible to the intended audience. Direct playback is useful evidence, but it does not prove that embedding is permitted.
Compare the page in a fresh browser session before consent, after the applicable consent choice, and after a reload. Do not test only in your logged-in administrator session. That session may already contain permissions or consent choices that an ordinary visitor does not have.
Did WordPress Create an Embed?
Use the WordPress YouTube block documentation to confirm the intended block workflow. A URL displayed as plain text is a different problem from a rendered player with a playback error. Test a normal supported video URL in a disposable draft and inspect the resulting block.
On the frontend, inspect whether an iframe exists, whether it has a real source, and whether a consent placeholder replaces it. Do not paste arbitrary iframe markup into every broken block. That can bypass the mechanism responsible for consent or produce another inconsistent page component.
Denied state: Respect the visitor choice. Allowed state: Player initializes as intended. Reload: Stored choice is respected. Accessibility: Placeholder is keyboard operable. Explanatory checklist, not a customer test result.
Read the Failure at the Correct Layer
| Evidence |
Next step |
| No embed element or placeholder |
Check saved block and page rendering |
| Consent placeholder appears |
Test its allowed and denied states |
| Player displays an availability message |
Check video restrictions and embed permission |
| Browser Console reports a policy block |
Review the named CSP or browser restriction |
YouTube's embedding guidance covers embedding restrictions and Privacy Enhanced Mode. That mode should not be described as a universal guarantee of zero data processing or legal compliance. Choose the implementation with your site's privacy requirements in mind, and preserve the user's consent choice during troubleshooting.
If the browser reports a Content Security Policy violation, capture the blocked URL and directive. Ask the policy owner to authorize the required trusted source narrowly. Do not remove the entire policy or allow every domain just to make one video play.
Test the Consent Transition
A useful acceptance test has three recorded outcomes: the denied state behaves as designed, the allowed state can initialize the player, and a new page load respects the stored choice. Also test keyboard access to the placeholder or consent control.
If changing consent makes the player work only after reloading, investigate the integration's initialization behavior. If the player works in one browser but not another, compare extensions and browser privacy settings in a clean test profile without telling visitors to weaken their privacy settings as the permanent fix.
For actual insecure resource URLs, follow WordPress mixed-content repair. For a copied page with the wrong embedded component, use the duplicate-page checklist. Request a targeted fix with the player message, consent state, and first Console error rather than only a screenshot of an empty box.
References reviewed October 6, 2026. Examples are explanatory, not customer test results.