DMCA WaterMarker Security & Risk Analysis

wordpress.org/plugins/dmca-watermarker

The DMCA WaterMarker plugin for WordPress lets you enable DMCA WaterMarking for a specific folder on your site in order to deter image thieves and pro …

10 active installs v1.1 PHP + WP 3.2+ Updated Apr 29, 2014
copyrightdmcaprotected-urltokenwatermarker
85
A · Safe
CVEs total1
Unpatched0
Last CVEMay 28, 2014
Safety Verdict

Is DMCA WaterMarker Safe to Use in 2026?

Generally Safe

Score 85/100

DMCA WaterMarker has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: May 28, 2014Updated 11yr ago
Risk Assessment

The "dmca-watermarker" v1.1 plugin exhibits a mixed security posture. On one hand, the static analysis shows a lack of direct attack surface in terms of AJAX handlers, REST API routes, shortcodes, and cron events, with no identified critical or high-severity taint flows. SQL queries are also exclusively using prepared statements, which is a positive practice. However, a significant concern arises from the low percentage of properly escaped output (40%), indicating a substantial risk of Cross-Site Scripting (XSS) vulnerabilities where user-supplied data is displayed without adequate sanitization. Furthermore, the complete absence of nonce and capability checks across all entry points, coupled with a history of XSS vulnerabilities, significantly elevates the risk profile. The plugin's last known vulnerability was in 2014, and while there are no currently unpatched CVEs, the historical pattern of XSS issues and the lack of modern security controls suggest potential underlying weaknesses that may not have been addressed in this older version.

Key Concerns

  • Low output escaping (40%)
  • No nonce checks
  • No capability checks
  • Historical XSS vulnerabilities
Vulnerabilities
1

DMCA WaterMarker Security Vulnerabilities

CVEs by Year

1 CVE in 2014
2014
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2014-4520medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

DMCA WaterMarker < 1.1 - Cross-Site Scripting

May 28, 2014 Patched in 1.1 (3527d)
Code Analysis
Analyzed Mar 17, 2026

DMCA WaterMarker Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
48
32 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
12
Bundled Libraries
0

Output Escaping

40% escaped80 total outputs
Attack Surface

DMCA WaterMarker Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actionplugins_loadeddmca-wm.php:53
actionadmin_menudmca-wm.php:54
actionadmin_menudmca-wm.php:55
actionadmin_initdmca-wm.php:56
actionadmin_initdmca-wm.php:57
actionadmin_initdmca-wm.php:58
filterplugin_action_linksdmca-wm.php:60
filterthe_contentdmca-wm.php:64
actionin_admin_footerdmca-wm.php:784
Maintenance & Trust

DMCA WaterMarker Maintenance & Trust

Maintenance Signals

WordPress version tested3.2.1
Last updatedApr 29, 2014
PHP min version
Downloads5K

Community Trust

Rating60/100
Number of ratings1
Active installs10
Developer Profile

DMCA WaterMarker Developer Profile

NewClarity

4 plugins · 1K total installs

70
trust score
Avg Security Score
87/100
Avg Patch Time
3527 days
View full developer profile
Detection Fingerprints

How We Detect DMCA WaterMarker

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/dmca-watermarker/style-settings-page.css
Version Parameters
dmca-watermarker/style-settings-page.css?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about DMCA WaterMarker