Lumière Movies Security & Risk Analysis

wordpress.org/plugins/lumiere-movies

Lumière! Movies is a WordPress plugin that retrieves data from www.imdb.com and helps you include it in your posts and in your widgets.

40 active installs v4.7.3 PHP 8.1+ WP 6.1+ Updated Dec 25, 2025
actorcinemafilmimdbmovie
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Lumière Movies Safe to Use in 2026?

Generally Safe

Score 100/100

Lumière Movies has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The "lumiere-movies" plugin v4.7.3 exhibits a generally strong security posture, with a notable absence of known vulnerabilities in its history. The code analysis reveals excellent practices in database interactions, with 100% of SQL queries utilizing prepared statements, and a high percentage of output being properly escaped. Furthermore, a significant number of nonce and capability checks indicate a conscious effort towards secure development. The plugin also avoids making external HTTP requests, reducing potential attack vectors.

However, there are specific areas of concern that slightly detract from its otherwise good standing. The presence of two AJAX handlers without authentication checks represents a significant potential risk. These unprotected entry points could be exploited by unauthenticated users to perform unintended actions if they are not sufficiently validated internally. While taint analysis showed no immediate issues, the lack of sanitization on these AJAX endpoints could lead to vulnerabilities if user input is not handled with extreme care within the handler functions themselves.

In conclusion, "lumiere-movies" v4.7.3 is a relatively secure plugin, bolstered by a clean vulnerability history and good coding practices in critical areas. The primary weakness lies in the two unprotected AJAX handlers, which should be a priority for remediation to fully secure the plugin's attack surface.

Key Concerns

  • Unprotected AJAX handlers
Vulnerabilities
None known

Lumière Movies Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Lumière Movies Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
8 prepared
Unescaped Output
41
872 escaped
Nonce Checks
25
Capability Checks
10
File Operations
1
External Requests
0
Bundled Libraries
1

Bundled Libraries

TinyMCE

SQL Query Safety

100% prepared8 total queries

Output Escaping

96% escaped913 total outputs
Attack Surface
2 unprotected

Lumière Movies Attack Surface

Entry Points4
Unprotected2

AJAX Handlers 2

authwp_ajax_amp_comment_submitclass\Theme\Taxonomy_People_Standard.php:110
noprivwp_ajax_amp_comment_submitclass\Theme\Taxonomy_People_Standard.php:111

Shortcodes 2

[imdblt] class\Frontend\Post\Front_Parser.php:91
[imdbltid] class\Frontend\Post\Front_Parser.php:92
WordPress Hooks 103
filtertemplate_redirectclass\Admin\Admin.php:65
actioninitclass\Admin\Admin.php:68
actionadmin_initclass\Admin\Admin.php:78
actionadmin_initclass\Admin\Admin.php:81
actionadmin_enqueue_scriptsclass\Admin\Admin.php:84
actionadmin_enqueue_scriptsclass\Admin\Admin.php:87
actionadmin_enqueue_scriptsclass\Admin\Admin.php:90
actioninitclass\Admin\Admin.php:100
actioninitclass\Admin\Admin.php:103
filtermce_external_pluginsclass\Admin\Admin.php:224
filtermce_buttonsclass\Admin\Admin.php:225
actionadmin_noticesclass\Admin\Admin_Menu.php:129
actionadmin_noticesclass\Admin\Admin_Menu.php:130
actionwp_loadedclass\Admin\Admin_Menu.php:146
actioninitclass\Admin\Admin_Menu.php:147
actionadmin_initclass\Admin\Admin_Menu.php:157
actionadmin_menuclass\Admin\Admin_Menu.php:167
actionadmin_bar_menuclass\Admin\Admin_Menu.php:173
actionadmin_noticesclass\Admin\Admin_Notifications.php:65
filterplugin_row_metaclass\Admin\Backoffice_Extra.php:28
filterplugin_action_linksclass\Admin\Backoffice_Extra.php:31
actionadmin_initclass\Admin\Backoffice_Extra.php:34
actionadmin_noticesclass\Admin\Copy_Templates\Detect_New_Theme.php:77
actionadmin_noticesclass\Admin\Copy_Templates\Detect_New_Theme.php:82
actionlumiere_exec_once_updateclass\Admin\Crons\Cron.php:57
actionlumiere_cron_deletecacheoversizedclass\Admin\Crons\Cron.php:60
actionlumiere_cron_autofreshcacheclass\Admin\Crons\Cron.php:63
actioninitclass\Admin\Crons\Cron.php:66
filtercron_schedulesclass\Admin\Crons\Cron.php:69
actionsave_postclass\Admin\Metabox_Selection.php:80
actionadmin_initclass\Admin\Save\Save_Options.php:39
actioninitclass\Admin\Save\Save_Options.php:76
actionwp_enqueue_scriptsclass\Admin\Search_Items.php:61
actionwp_enqueue_scriptsclass\Admin\Search_Items.php:62
actionwp_enqueue_scriptsclass\Admin\Search_Items.php:65
filtertemplate_includeclass\Admin\Search_Items.php:71
filterdocument_title_partsclass\Admin\Search_Items.php:77
filtershow_admin_barclass\Admin\Search_Items.php:105
actionwidgets_initclass\Admin\Widget_Selection.php:67
actionwidgets_initclass\Admin\Widget_Selection.php:102
actioninitclass\Admin\Widget_Selection.php:112
filterquery_varsclass\Alteration\Rewrite_Rules.php:41
filtergenerate_rewrite_rulesclass\Alteration\Rewrite_Rules.php:44
filterlum_add_rewrite_rules_if_adminclass\Alteration\Rewrite_Rules.php:51
filterpll_rewrite_rulesclass\Alteration\Rewrite_Rules.php:99
actioninitclass\Alteration\Taxonomy.php:57
actioninitclass\Alteration\Taxonomy.php:61
actionwidgets_initclass\Core.php:53
actioninitclass\Core.php:58
actioninitclass\Core.php:63
actioninitclass\Core.php:68
actioninitclass\Core.php:73
actioninitclass\Core.php:78
actioninitclass\Core.php:83
actionenqueue_block_editor_assetsclass\Core.php:84
actioncli_initclass\Core.php:88
actionwp_enqueue_scriptsclass\Frontend\Frontend.php:53
actionwp_enqueue_scriptsclass\Frontend\Frontend.php:56
actioninitclass\Frontend\Frontend.php:61
filterlum_display_movies_boxclass\Frontend\Frontend.php:62
filterlum_display_persons_boxclass\Frontend\Frontend.php:63
filterlum_find_movie_idclass\Frontend\Frontend.php:64
filterlum_find_person_idclass\Frontend\Frontend.php:65
filterlum_coming_soonclass\Frontend\Frontend.php:70
actioninitclass\Frontend\Frontend.php:75
filtertemplate_includeclass\Frontend\Frontend.php:80
actionwp_enqueue_scriptsclass\Frontend\Link_Maker\Bootstrap_Links.php:35
actionwp_enqueue_scriptsclass\Frontend\Link_Maker\Bootstrap_Links.php:38
actionwp_enqueue_scriptsclass\Frontend\Link_Maker\Classic_Links.php:38
actionwp_enqueue_scriptsclass\Frontend\Link_Maker\Classic_Links.php:41
actionwp_enqueue_scriptsclass\Frontend\Link_Maker\Highslide_Links.php:39
actionwp_enqueue_scriptsclass\Frontend\Link_Maker\Highslide_Links.php:42
actionwp_headclass\Frontend\Popups\Head_Popups.php:83
actionwp_headclass\Frontend\Popups\Head_Popups.php:89
filtershow_admin_barclass\Frontend\Popups\Head_Popups.php:133
filterdocument_title_partsclass\Frontend\Popups\Popup_Film.php:117
filterdocument_title_partsclass\Frontend\Popups\Popup_Movie_Search.php:74
filterdocument_title_partsclass\Frontend\Popups\Popup_Person.php:114
filterthe_contentclass\Frontend\Post\Front_Parser.php:81
filterthe_contentclass\Frontend\Post\Front_Parser.php:84
filterthe_excerptclass\Frontend\Post\Front_Parser.php:85
actionwidgets_initclass\Frontend\Widget\Widget_Legacy.php:41
actionautomatic_updates_completeclass\Hooks_Updates.php:38
actionupgrader_process_completeclass\Hooks_Updates.php:39
actionadmin_initclass\Hooks_Updates.php:42
actionadmin_noticesclass\Hooks_Updates.php:145
filteraioseo_disableclass\Plugins\Auto\Aioseo.php:42
actionwp_enqueue_scriptsclass\Plugins\Auto\Amp.php:41
actionwp_enqueue_scriptsclass\Plugins\Auto\Amp.php:44
actionamp_mobile_version_switcher_link_textclass\Plugins\Auto\Amp.php:92
filterthe_contentclass\Plugins\Auto\Irp.php:48
actionwp_enqueue_scriptsclass\Plugins\Auto\Oceanwp.php:61
actionwp_enqueue_scriptsclass\Plugins\Auto\Oceanwp.php:64
actionwp_enqueue_scriptsclass\Plugins\Auto\Oceanwp.php:65
filterlum_polylang_rewrite_url_with_langclass\Plugins\Auto\Polylang.php:55
filterlum_polylang_taxo_queryclass\Plugins\Auto\Polylang.php:58
filterpll_get_taxonomiesclass\Plugins\Auto\Polylang.php:61
filterlum_polylang_form_taxonomy_peopleclass\Plugins\Auto\Polylang.php:64
filterpll_get_taxonomiesclass\Plugins\Auto\Polylang.php:95
filterlum_polylang_update_taxonomy_termsclass\Plugins\Auto\Polylang.php:98
actionlum_maybe_ban_bots_generalclass\Tools\Ban_Bots.php:59
actionlum_maybe_ban_bots_noreferrerclass\Tools\Ban_Bots.php:60
actionadmin_noticesfunctions.php:49

Scheduled Events 3

lumiere_cron_deletecacheoversized
lumiere_cron_autofreshcache
lumiere_exec_once_update
Maintenance & Trust

Lumière Movies Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 25, 2025
PHP min version8.1
Downloads10K

Community Trust

Rating100/100
Number of ratings3
Active installs40
Developer Profile

Lumière Movies Developer Profile

JCV

1 plugin · 40 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Lumière Movies

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/lumiere-movies/assets/css/lumiere_admin.min.css/wp-content/plugins/lumiere-movies/assets/js/lumiere_scripts_admin.min.js/wp-content/plugins/lumiere-movies/assets/js/lumiere_hide_show.min.js/wp-content/plugins/lumiere-movies/assets/js/lumiere_admin_deactivation_msg.min.js/wp-content/plugins/lumiere-movies/assets/js/lumiere_admin_quicktags.min.js
Script Paths
/wp-content/plugins/lumiere-movies/assets/js/lumiere_hide_show.min.js/wp-content/plugins/lumiere-movies/assets/js/lumiere_scripts_admin.min.js/wp-content/plugins/lumiere-movies/assets/js/lumiere_admin_deactivation_msg.min.js/wp-content/plugins/lumiere-movies/assets/js/lumiere_admin_quicktags.min.js

HTML / DOM Fingerprints

JS Globals
window.lum_optionswindow.lumiere_quicktags
FAQ

Frequently Asked Questions about Lumière Movies