
Movie Widget Security & Risk Analysis
wordpress.org/plugins/movie-widgetMovie widget displays movie posters, trailers and descriptions. It can also do TV shows as well.
Is Movie Widget Safe to Use in 2026?
Generally Safe
Score 85/100Movie Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The movie-widget plugin v1.0.2 exhibits a strong security posture based on the provided static analysis. The complete absence of direct attack surface entries such as AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's exposure to external manipulation. Furthermore, the code signals are overwhelmingly positive, with no dangerous functions identified, all SQL queries utilizing prepared statements, and a high percentage of output properly escaped. The lack of file operations and external HTTP requests, alongside the absence of taint analysis findings, further reinforces this assessment.
However, there are a few areas that warrant attention. The absence of nonce checks and capability checks across all identified entry points (even though there are zero entry points) is a notable omission. While the plugin currently has no identified attack surface, if any were to be introduced in future versions without these security measures, it would immediately become vulnerable. The presence of two external HTTP requests, while not inherently a vulnerability, represents a potential vector for supply chain attacks or information disclosure if not handled securely. The plugin's vulnerability history is clean, with no known CVEs, which is an excellent indicator of its past security practices. Overall, the plugin is very well-developed from a security standpoint, with only minor points of consideration for future development.
Key Concerns
- No nonce checks found
- No capability checks found
- Two external HTTP requests present
Movie Widget Security Vulnerabilities
Movie Widget Code Analysis
Output Escaping
Movie Widget Attack Surface
WordPress Hooks 2
Maintenance & Trust
Movie Widget Maintenance & Trust
Maintenance Signals
Community Trust
Movie Widget Alternatives
Latest Apple Movie Trailers
latest-apple-movie-trailers
Displays the latest movie trailers featured on Apple.com via the RSS Feed.
Trustami Badge for Customer Reviews and Google Stars
trustami-badge-for-customer-reviews-and-google-stars
Trustami plugin for WooCommerce. Trustami - One badge for all your customer reviews. Trustami collects, analyzes and presents a users' distribute …
ČSFD Last Seen
csfd-last-seen
ČSFD Last Seen plugin adds a widget, which shows the last X movies rated on CSFD.cz (Czech-Slovak movie database).
iCheckMovies Widget
icheckmovies-widget
Looks cool to share your latest seen movies on your blog.
XTCZ Top Box Office
xtcz-top-box-office
Real time Weekend Box Office results on your blog.
Movie Widget Developer Profile
1 plugin · 40 total installs
How We Detect Movie Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/movie-widget/css/style.css/wp-content/plugins/movie-widget/js/main.jshttps://apis.google.com/js/platform.jsmovie-widget/css/style.css?ver=movie-widget/js/main.js?ver=