ILC FLVBox Security & Risk Analysis

wordpress.org/plugins/ilc-flvbox

Plays FLV video inline in content or in a modal dialog.

10 active installs v1.0.5 PHP + WP 2.6+ Updated Mar 26, 2009
adminflvmodal-dialogthickboxvideo
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is ILC FLVBox Safe to Use in 2026?

Generally Safe

Score 85/100

ILC FLVBox has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 17yr ago
Risk Assessment

The ilc-flvbox plugin exhibits a mixed security posture. On the positive side, there are no recorded vulnerabilities (CVEs) or critical taint flows, indicating a lack of publicly known exploits and a potentially safe coding history. The static analysis also shows no dangerous functions, no external HTTP requests, and all SQL queries are properly prepared, which are good security practices. However, significant concerns arise from the complete absence of output escaping. With 20 total outputs analyzed and 0% properly escaped, this presents a high risk of Cross-Site Scripting (XSS) vulnerabilities. Any user-provided data displayed by the plugin without proper sanitization could be exploited to inject malicious scripts, leading to session hijacking, defacement, or further attacks. Additionally, the complete lack of nonce checks and capability checks on all entry points, although currently small in number, suggests a potential for Cross-Site Request Forgery (CSRF) if any functionality were to be added that modifies data. While the plugin's current attack surface is minimal and it doesn't appear to have a history of vulnerabilities, the lack of basic output escaping is a critical flaw that significantly increases its risk profile.

Key Concerns

  • 0% output properly escaped
  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
None known

ILC FLVBox Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

ILC FLVBox Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
20
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
4
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped20 total outputs
Attack Surface

ILC FLVBox Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actioninitflvbox.php:108
actionwp_headflvbox.php:109
filterthe_contentflvbox.php:110
filterplugin_action_linksflvbox.php:258
actionadmin_menuflvbox.php:261
Maintenance & Trust

ILC FLVBox Maintenance & Trust

Maintenance Signals

WordPress version tested2.7
Last updatedMar 26, 2009
PHP min version
Downloads5K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

ILC FLVBox Developer Profile

Elio Rivero

3 plugins · 60 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect ILC FLVBox

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ilc-flvbox/flvbox.css
Script Paths
/wp-content/plugins/ilc-flvbox/swfobject15.js
Version Parameters
ilc-flvbox/flvbox.css?ver=swfobject15.js?ver=

HTML / DOM Fingerprints

CSS Classes
ilc_flvbox_inlineimgilc_flvbox_playflvbox_inline
HTML Comments
<!-- begin ilc_flvbox scripts --><!-- end ilc_flvbox scripts -->
Data Attributes
ilc_flvbox_tbilc_flvbox_osflv_divilc_flvbox_osflv_bgcolorilc_flvbox_osflv_fgcolorilc_flvbox_osflv_volumeilc_flvbox_width+4 more
JS Globals
tb_pathToImagetb_closeImageilc_loadVideoverbgcso
Shortcode Output
<a href="#TB_inline?height=&width=&inlineId=ilc_flvbox_content" class="thickbox flvbox"><div class="ilc_flvbox_play"></div><img src=
FAQ

Frequently Asked Questions about ILC FLVBox