
NanTuki YiFy-Torrent Adder Security & Risk Analysis
wordpress.org/plugins/nantuki-yify-torrent-adderDisplay movie information from YTS in wordpress post, it includes all the fields that are in IMDB, including screenshots of the movie and direct torre …
Is NanTuki YiFy-Torrent Adder Safe to Use in 2026?
Generally Safe
Score 85/100NanTuki YiFy-Torrent Adder has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "nantuki-yify-torrent-adder" plugin version 1.0 exhibits a mixed security posture. On the positive side, the plugin has no known CVEs and uses prepared statements for its SQL queries. The attack surface appears minimal with only one shortcode and no AJAX handlers or REST API routes exposed without checks. However, several significant concerns arise from the static analysis. The complete absence of output escaping for all 33 identified outputs is a critical vulnerability, opening the door to cross-site scripting (XSS) attacks. Furthermore, the lack of nonce and capability checks means that the shortcode handler is likely unprotected, allowing unauthenticated users to trigger its functionality, potentially leading to unintended actions or information disclosure. The plugin also performs file operations without any apparent sanitization or permission checks, which could be exploited for file manipulation or directory traversal. The lack of vulnerability history might suggest it hasn't been widely targeted or analyzed, but the current code analysis reveals critical weaknesses that need immediate attention.
Key Concerns
- Unescaped output (all 33 outputs)
- Shortcode without capability checks
- File operations without apparent checks
- Missing nonce checks
NanTuki YiFy-Torrent Adder Security Vulnerabilities
NanTuki YiFy-Torrent Adder Code Analysis
Output Escaping
NanTuki YiFy-Torrent Adder Attack Surface
Shortcodes 1
WordPress Hooks 1
Maintenance & Trust
NanTuki YiFy-Torrent Adder Maintenance & Trust
Maintenance Signals
Community Trust
NanTuki YiFy-Torrent Adder Alternatives
Lumière Movies
lumiere-movies
Lumière! Movies is a WordPress plugin that retrieves data from www.imdb.com and helps you include it in your posts and in your widgets.
F13 Movies
f13-movie-shortcode
Do you blog about movies? It can be tedious adding movie information manually, now you can add movie information with shortcode using an IMDB ID.
IMDb API
wp-imdb-api
The IMDb API is a RESTful web service to obtain movie information, all content and images on the site are contributed and maintained by our users.
FilmGetter
filmgetter
FilmGetter uses tags to show information like Poster, plot, rating, release date, TMDb and imdb urls.
iCheckMovies Widget
icheckmovies-widget
Looks cool to share your latest seen movies on your blog.
NanTuki YiFy-Torrent Adder Developer Profile
1 plugin · 10 total installs
How We Detect NanTuki YiFy-Torrent Adder
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
[yts id="ytsmovieid"]