
Airliners Widget Security & Risk Analysis
wordpress.org/plugins/airliners-widgetDisplays an Airliners.net picture (Random, Top Of Yesterday, or specific picture by ID) using official Airliners.net script
Is Airliners Widget Safe to Use in 2026?
Generally Safe
Score 85/100Airliners Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The airliners-widget plugin, version 1.1.1, exhibits a generally positive security posture based on the provided static analysis and vulnerability history. The absence of known CVEs and the complete lack of critical or high-severity issues in its history are strong indicators of a well-maintained and secure plugin. Furthermore, the static analysis reveals no direct SQL injection vulnerabilities through prepared statements, no file operations, and no external HTTP requests, all of which significantly reduce common attack vectors. The plugin also has a very small attack surface with only one shortcode and no unprotected AJAX or REST API entry points.
However, there are areas for improvement. The most notable concern is the low percentage (25%) of properly escaped outputs. This indicates a potential for Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is directly rendered without adequate sanitization. While the taint analysis shows no identified flows, this might be due to the limited scope of analysis or the specific nature of the data processed. The absence of nonce checks and capability checks on the single shortcode, while not immediately exploitable given the lack of other weaknesses, represents a missed opportunity for robust access control and could become a risk if the plugin's functionality were to evolve to handle sensitive operations.
In conclusion, airliners-widget v1.1.1 is a relatively secure plugin, particularly due to its clean vulnerability history and the absence of critical static analysis findings. The primary area of concern is output escaping, which needs attention to mitigate XSS risks. The lack of authorization checks on the shortcode is a minor point but worth noting for future development. Overall, the strengths outweigh the weaknesses, but addressing the output escaping would further solidify its security.
Key Concerns
- Low output escaping percentage
- Missing nonce checks on shortcode
- Missing capability checks on shortcode
Airliners Widget Security Vulnerabilities
Airliners Widget Code Analysis
Output Escaping
Airliners Widget Attack Surface
Shortcodes 1
WordPress Hooks 1
Maintenance & Trust
Airliners Widget Maintenance & Trust
Maintenance Signals
Community Trust
Airliners Widget Alternatives
JJ NextGen JQuery Slider
jj-nextgen-jquery-slider
Allows you to pick a gallery from the 'NextGen Gallery' plugin to use as a 'JQuery Nivo slider'.
NextGEN Gallery Sidebar Widget
nextgen-gallery-sidebar-widget
A widget to show NextGEN galleries in your sidebar.
Image Widget by Angie Makes
wpc-image-widget
This plugin allows for the addition of a drag / drop image widget to the existing widgets in your Wordpress theme. Easily upload, and link images to t …
JJ NextGen JQuery Carousel
jj-nextgen-jquery-carousel
Allows you to pick a gallery from the 'NextGen Gallery' plugin to use as a 'JQuery JCarousel'.
NextGen NivoSlider
nextgen-nivoslider
The NextGen Nivoslider plugin allows you to create a NivoSlider, using images from your NextGen gallery, with a simple shortcode or widget.
Airliners Widget Developer Profile
3 plugins · 70 total installs
How We Detect Airliners Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/airliners-widget/airliners-widget.cssairliners-widget.css?ver=HTML / DOM Fingerprints
widget_airliners_widgetid="airliners-widget-title"name="airliners-widget-title"id="airliners-widget-imgtype"name="airliners-widget-imgtype"id="airliners-widget-imgid"name="airliners-widget-imgid"<div class='widget_airliners_widget'>