
FilmGetter Security & Risk Analysis
wordpress.org/plugins/filmgetterFilmGetter uses tags to show information like Poster, plot, rating, release date, TMDb and imdb urls.
Is FilmGetter Safe to Use in 2026?
Generally Safe
Score 85/100FilmGetter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'filmgetter' v0.1.4.1 presents a concerning security posture despite its minimal apparent attack surface. While the plugin boasts zero AJAX handlers, REST API routes, shortcodes, and cron events, this lack of entry points does not translate to overall safety. The static analysis reveals significant weaknesses, most notably that 0% of its 3 total outputs are properly escaped, posing a high risk of Cross-Site Scripting (XSS) vulnerabilities. Furthermore, two taint flows were identified with unsanitized paths, rated as high severity, indicating potential for arbitrary file read or write operations, or other path traversal vulnerabilities. The complete absence of nonce and capability checks on any entry points (even though the static analysis reports 0 unprotected entry points, the lack of checks is a structural flaw if any were to be introduced) is a major red flag, as it allows any authenticated user to trigger plugin functionality, potentially leading to privilege escalation or unauthorized actions. The plugin's SQL usage is mixed, with 77% of queries using prepared statements, which is a positive sign, but the remaining 23% are not accounted for and could represent a risk if they are not properly sanitized. The absence of any known CVEs is a positive indicator, but given the identified code-level risks, this might be due to a lack of thorough auditing rather than inherent security. In conclusion, 'filmgetter' v0.1.4.1 exhibits critical weaknesses in output escaping and taint handling, coupled with a dangerous lack of security checks, making it a high-risk plugin despite its limited entry points.
Key Concerns
- No output escaping
- High severity unsanitized path taint flows
- No nonce checks
- No capability checks
FilmGetter Security Vulnerabilities
FilmGetter Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
FilmGetter Attack Surface
WordPress Hooks 5
Maintenance & Trust
FilmGetter Maintenance & Trust
Maintenance Signals
Community Trust
FilmGetter Alternatives
Lumière Movies
lumiere-movies
Lumière! Movies is a WordPress plugin that retrieves data from www.imdb.com and helps you include it in your posts and in your widgets.
MAS Videos
masvideos
MAS Videos is a free plugin that allows you to to create and list movies, videos and TV shows.
My Movie Database
my-movie-database
My Movie Database allows you to easily add detailed information about movies, tv shows and people you choose. The data comes from the Movie Database ( …
WP Film Studio – WordPress Movie Maker/Production Plugin
wp-film-studio
WP Film Studio is a WordPress Movie Maker/Production Plugin.
GeeK! – Movie & Game Database
geekpress
The GeeK plugin is a comprehensive tool for WordPress, enabling the creation of detailed movie and game databases.
FilmGetter Developer Profile
1 plugin · 10 total installs
How We Detect FilmGetter
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/filmgetter/style.cssfilmgetter/style.css?ver=HTML / DOM Fingerprints
[film][/film][imdb][/imdb]