
CineLink Embeds for JustWatch Security & Risk Analysis
wordpress.org/plugins/cinelink-embeds-for-justwatchEmbed JustWatch streaming availability widgets in the block editor with global defaults and per-block overrides.
Is CineLink Embeds for JustWatch Safe to Use in 2026?
Generally Safe
Score 100/100CineLink Embeds for JustWatch has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The cinelink-embeds-for-justwatch plugin, version 1.0.2, exhibits a generally strong security posture based on the provided static analysis. It adheres to several best practices, including the exclusive use of prepared statements for SQL queries and proper output escaping for all identified outputs. The absence of dangerous functions, file operations, and external HTTP requests further contributes to its secure design. The plugin also demonstrates a clean vulnerability history with no known CVEs, indicating a history of stable and secure development.
However, a notable concern arises from the lack of nonce checks and the presence of only one capability check across all identified entry points, which consists of a single shortcode. While the attack surface is minimal (1 entry point), the absence of robust authorization mechanisms for this shortcode, especially if it handles user-provided data or interacts with sensitive features, presents a potential risk. The taint analysis showing zero flows, while positive, might be limited by the scope of the analysis itself, and the minimal attack surface could mean that complex attack vectors are not easily discoverable.
In conclusion, the plugin is well-coded with respect to fundamental security practices like prepared statements and output escaping, and has a clean history. The primary area for improvement and potential risk lies in strengthening the authorization and validation of its sole shortcode entry point to prevent potential misuse.
Key Concerns
- Missing nonce checks on shortcode
- Limited capability checks on entry points
CineLink Embeds for JustWatch Security Vulnerabilities
CineLink Embeds for JustWatch Release Timeline
CineLink Embeds for JustWatch Code Analysis
Output Escaping
CineLink Embeds for JustWatch Attack Surface
Shortcodes 1
WordPress Hooks 7
Maintenance & Trust
CineLink Embeds for JustWatch Maintenance & Trust
Maintenance Signals
Community Trust
CineLink Embeds for JustWatch Alternatives
JustWatch – Partner Integrations
justwatch-partner-integrations
Connect your audience to the best streaming services worldwide.
MAS Videos
masvideos
MAS Videos is a free plugin that allows you to to create and list movies, videos and TV shows.
My Movie Database
my-movie-database
My Movie Database allows you to easily add detailed information about movies, tv shows and people you choose. The data comes from the Movie Database ( …
Kw LiveStream Plugin
kw-livestream-plugin
A simple plugin for streaming (live tv) with livestream.com and shortcode with WordPress. Multiple livestream possibility
Netflix Buttons
netflix-buttons
This is a simple plugin to add the Netflix add, play, or save buttons for a movie to any post/page.
CineLink Embeds for JustWatch Developer Profile
1 plugin · 0 total installs
How We Detect CineLink Embeds for JustWatch
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cinelink-embeds-for-justwatch/assets/justwatch-widget.csshttps://widget.justwatch.com/justwatch_widget.jscinelink-embeds-for-justwatch/assets/justwatch-widget.css?ver=HTML / DOM Fingerprints
window.jwWidgetsGlobalDefaults[cinelink