
JJ SwfObject Security & Risk Analysis
wordpress.org/plugins/jj-swfobjectAllows you to insert a swf file using a widget or a shortcode using the swfobject library.
Is JJ SwfObject Safe to Use in 2026?
Generally Safe
Score 85/100JJ SwfObject has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "jj-swfobject" v1.0.5 plugin exhibits a mixed security posture. On the positive side, there are no identified CVEs in its history, no SQL queries are vulnerable to injection, and there are no external HTTP requests or file operations, reducing common attack vectors. The plugin also presents a minimal attack surface with only one shortcode and no unprotected entry points.
However, significant concerns arise from the static analysis. The presence of the `create_function` dangerous function is a notable risk, as it can be a vector for arbitrary code execution in certain contexts. Furthermore, the extremely low rate of properly escaped output (4%) is a critical vulnerability. This means that data displayed to users, potentially sourced from user input, is likely to be unescaped, creating a high risk of Cross-Site Scripting (XSS) attacks. The complete absence of nonce checks and capability checks on any entry points further exacerbates this risk, allowing unauthenticated or unauthorized users to potentially trigger vulnerabilities.
In conclusion, while the plugin has a clean vulnerability history and avoids some common pitfalls like raw SQL and external requests, the severe lack of output escaping and the presence of a dangerous function, coupled with no permission checks, make it a high-risk plugin. The absence of any taint analysis results is also noteworthy but doesn't override the direct code signals of risk.
Key Concerns
- High percentage of unescaped output
- Presence of dangerous function 'create_function'
- No nonce checks on entry points
- No capability checks on entry points
JJ SwfObject Security Vulnerabilities
JJ SwfObject Release Timeline
JJ SwfObject Code Analysis
Dangerous Functions Found
Output Escaping
JJ SwfObject Attack Surface
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
JJ SwfObject Maintenance & Trust
Maintenance Signals
Community Trust
JJ SwfObject Alternatives
WP-SWFObject
wp-swfobject
Insert Flash Movies into WordPress.
Easy Flash Embed
easy-flash-embed
Embed Flash easily and standard compliant with SWFObject using only a [swf] shortcode!
Flash Feed Scroll Reader
flash-feed-scroll-reader
Flash Feed Scroll Reader is a Adobe Flash Feed Reader with horizontal scrolling.
SWFObject jQuery
swfobjectjquery
A simple plugins that uses jQuery and SWFObject!
Contact Form by BestWebSoft – Advanced WP Contact Form Builder for WordPress
contact-form-plugin
The most powerful and user-friendly WordPress contact form plugin. Create beautiful contact forms, widgets and pages using shortcodes.
JJ SwfObject Developer Profile
6 plugins · 2K total installs
How We Detect JJ SwfObject
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/jj-swfobject/swfobject/swfobject.js/wp-content/plugins/jj-swfobject/stylesheets/style.css/wp-content/plugins/jj-swfobject/swfobject/swfobject.jsjj-swfobject/swfobject/swfobject.js?ver=jj-swfobject/stylesheets/style.css?ver=HTML / DOM Fingerprints
jj_swfobjectid="jj_swfobject"swfobject<div class="widget_jj_swfobject">