Movie Widget Security & Risk Analysis

wordpress.org/plugins/movie-widget

Movie widget displays movie posters, trailers and descriptions. It can also do TV shows as well.

40 active installs v1.0.2 PHP 7.2.4+ WP 5.3+ Updated Apr 18, 2021
movieoverviewposterstrailerswidget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Movie Widget Safe to Use in 2026?

Generally Safe

Score 85/100

Movie Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The movie-widget plugin v1.0.2 exhibits a strong security posture based on the provided static analysis. The complete absence of direct attack surface entries such as AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's exposure to external manipulation. Furthermore, the code signals are overwhelmingly positive, with no dangerous functions identified, all SQL queries utilizing prepared statements, and a high percentage of output properly escaped. The lack of file operations and external HTTP requests, alongside the absence of taint analysis findings, further reinforces this assessment.

However, there are a few areas that warrant attention. The absence of nonce checks and capability checks across all identified entry points (even though there are zero entry points) is a notable omission. While the plugin currently has no identified attack surface, if any were to be introduced in future versions without these security measures, it would immediately become vulnerable. The presence of two external HTTP requests, while not inherently a vulnerability, represents a potential vector for supply chain attacks or information disclosure if not handled securely. The plugin's vulnerability history is clean, with no known CVEs, which is an excellent indicator of its past security practices. Overall, the plugin is very well-developed from a security standpoint, with only minor points of consideration for future development.

Key Concerns

  • No nonce checks found
  • No capability checks found
  • Two external HTTP requests present
Vulnerabilities
None known

Movie Widget Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Movie Widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
65 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

90% escaped72 total outputs
Attack Surface

Movie Widget Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionwp_enqueue_scriptsincludes\movieposterdisplay-scripts.php:14
actionwidgets_initmovieposterdisplay.php:41
Maintenance & Trust

Movie Widget Maintenance & Trust

Maintenance Signals

WordPress version tested5.7.15
Last updatedApr 18, 2021
PHP min version7.2.4
Downloads7K

Community Trust

Rating100/100
Number of ratings2
Active installs40
Developer Profile

Movie Widget Developer Profile

John Son

1 plugin · 40 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Movie Widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/movie-widget/css/style.css/wp-content/plugins/movie-widget/js/main.js
Script Paths
https://apis.google.com/js/platform.js
Version Parameters
movie-widget/css/style.css?ver=movie-widget/js/main.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Movie Widget