CineLink Embeds for JustWatch Security & Risk Analysis

wordpress.org/plugins/cinelink-embeds-for-justwatch

Embed JustWatch streaming availability widgets in the block editor with global defaults and per-block overrides.

0 active installs v1.0.2 PHP 7.4+ WP 6.0+ Updated Mar 18, 2026
gutenbergjustwatchmoviesstreamingtv
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is CineLink Embeds for JustWatch Safe to Use in 2026?

Generally Safe

Score 100/100

CineLink Embeds for JustWatch has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The cinelink-embeds-for-justwatch plugin, version 1.0.2, exhibits a generally strong security posture based on the provided static analysis. It adheres to several best practices, including the exclusive use of prepared statements for SQL queries and proper output escaping for all identified outputs. The absence of dangerous functions, file operations, and external HTTP requests further contributes to its secure design. The plugin also demonstrates a clean vulnerability history with no known CVEs, indicating a history of stable and secure development.

However, a notable concern arises from the lack of nonce checks and the presence of only one capability check across all identified entry points, which consists of a single shortcode. While the attack surface is minimal (1 entry point), the absence of robust authorization mechanisms for this shortcode, especially if it handles user-provided data or interacts with sensitive features, presents a potential risk. The taint analysis showing zero flows, while positive, might be limited by the scope of the analysis itself, and the minimal attack surface could mean that complex attack vectors are not easily discoverable.

In conclusion, the plugin is well-coded with respect to fundamental security practices like prepared statements and output escaping, and has a clean history. The primary area for improvement and potential risk lies in strengthening the authorization and validation of its sole shortcode entry point to prevent potential misuse.

Key Concerns

  • Missing nonce checks on shortcode
  • Limited capability checks on entry points
Vulnerabilities
None known

CineLink Embeds for JustWatch Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

CineLink Embeds for JustWatch Release Timeline

v1.0.2Current
v1.0.1
v1.0.0
Code Analysis
Analyzed Apr 16, 2026

CineLink Embeds for JustWatch Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
137 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped137 total outputs
Attack Surface

CineLink Embeds for JustWatch Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[cinelink] cinelink-embeds-for-justwatch.php:85
WordPress Hooks 7
actioninitcinelink-embeds-for-justwatch.php:79
actionenqueue_block_editor_assetscinelink-embeds-for-justwatch.php:104
actionwp_enqueue_scriptscinelink-embeds-for-justwatch.php:137
actionadmin_menuincludes/admin-settings.php:41
filteradmin_footer_textincludes/admin-settings.php:53
actionadmin_enqueue_scriptsincludes/admin-settings.php:61
actionadmin_initincludes/admin-settings.php:86
Maintenance & Trust

CineLink Embeds for JustWatch Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 18, 2026
PHP min version7.4
Downloads375

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

CineLink Embeds for JustWatch Developer Profile

MatthewCSimpson

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect CineLink Embeds for JustWatch

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cinelink-embeds-for-justwatch/assets/justwatch-widget.css
Script Paths
https://widget.justwatch.com/justwatch_widget.js
Version Parameters
cinelink-embeds-for-justwatch/assets/justwatch-widget.css?ver=

HTML / DOM Fingerprints

JS Globals
window.jwWidgetsGlobalDefaults
Shortcode Output
[cinelink
FAQ

Frequently Asked Questions about CineLink Embeds for JustWatch