Blip TV Episodes Widget Security & Risk Analysis

wordpress.org/plugins/blip-tv-episodes-widget

Blip TV Episodes plugin will allow you to setup a video widget, easily add videos to posts then watch them appear in the sidebar when viewing that pos …

10 active installs v0.3 PHP + WP 2.8.6+ Updated Aug 7, 2014
bliptvblogbuildervideoyoutube
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Blip TV Episodes Widget Safe to Use in 2026?

Generally Safe

Score 85/100

Blip TV Episodes Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The blip-tv-episodes-widget plugin v0.3 exhibits a concerning security posture primarily due to significant weaknesses in its code practices, despite having no known historical vulnerabilities. The static analysis reveals a complete lack of output escaping and a high percentage of SQL queries that do not utilize prepared statements. This combination presents a substantial risk of cross-site scripting (XSS) and SQL injection vulnerabilities, as unsanitized data is likely being directly outputted or used in database queries. The taint analysis, while not reporting critical or high severity flows, did identify flows with unsanitized paths, which, when combined with the escaping and prepared statement issues, strongly suggests that these potential vulnerabilities exist in practice.

While the absence of known CVEs and a zero attack surface in terms of direct entry points (AJAX, REST API, shortcodes, cron) are positive indicators, they do not negate the inherent risks within the plugin's code. The lack of capability checks and nonce checks, though not directly linked to the identified attack surface, further indicates a general disregard for security best practices. The plugin's strengths lie in its seemingly small footprint and lack of historical issues, but its weaknesses in fundamental coding security practices create a high potential for exploitation.

Key Concerns

  • SQL queries lack prepared statements
  • No output escaping
  • Taint flows with unsanitized paths
  • No capability checks
  • No nonce checks
Vulnerabilities
None known

Blip TV Episodes Widget Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Blip TV Episodes Widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
4
0 prepared
Unescaped Output
18
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared4 total queries

Output Escaping

0% escaped18 total outputs
Data Flows
6 unsanitized

Data Flow Analysis

6 flows6 with unsanitized paths
blip_postlist_sidebarvideos (functions\blip_functions_interface.php:24)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Blip TV Episodes Widget Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_menublip-tv-episodes-widget.php:82
actionadmin_headblip-tv-episodes-widget.php:85
actionplugins_loadedblip-tv-episodes-widget.php:88
Maintenance & Trust

Blip TV Episodes Widget Maintenance & Trust

Maintenance Signals

WordPress version tested2.9.2
Last updatedAug 7, 2014
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Blip TV Episodes Widget Developer Profile

WebTechGlobal

4 plugins · 50 total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Blip TV Episodes Widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/blip-tv-episodes-widget/blip_home.php/wp-content/plugins/blip-tv-episodes-widget/functions/blip_functions_global.php/wp-content/plugins/blip-tv-episodes-widget/functions/blip_functions_interface.php/wp-content/plugins/blip-tv-episodes-widget/functions/blip_functions_processing.php/wp-content/plugins/blip-tv-episodes-widget/functions/blip_functions_installation.php/wp-content/plugins/blip-tv-episodes-widget/blip_manager.php/wp-content/plugins/blip-tv-episodes-widget/blip_settings.php/wp-content/plugins/blip-tv-episodes-widget/blip_tools.php+1 more
Version Parameters
blip-tv-episodes-widget/style.css?ver=blip-tv-episodes-widget/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
blip_widget
FAQ

Frequently Asked Questions about Blip TV Episodes Widget