NanTuki YiFy-Torrent Adder Security & Risk Analysis

wordpress.org/plugins/nantuki-yify-torrent-adder

Display movie information from YTS in wordpress post, it includes all the fields that are in IMDB, including screenshots of the movie and direct torre …

10 active installs v1.0 PHP + WP 2.8+ Updated Nov 14, 2014
imdbmovieshortcodeyts
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is NanTuki YiFy-Torrent Adder Safe to Use in 2026?

Generally Safe

Score 85/100

NanTuki YiFy-Torrent Adder has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The "nantuki-yify-torrent-adder" plugin version 1.0 exhibits a mixed security posture. On the positive side, the plugin has no known CVEs and uses prepared statements for its SQL queries. The attack surface appears minimal with only one shortcode and no AJAX handlers or REST API routes exposed without checks. However, several significant concerns arise from the static analysis. The complete absence of output escaping for all 33 identified outputs is a critical vulnerability, opening the door to cross-site scripting (XSS) attacks. Furthermore, the lack of nonce and capability checks means that the shortcode handler is likely unprotected, allowing unauthenticated users to trigger its functionality, potentially leading to unintended actions or information disclosure. The plugin also performs file operations without any apparent sanitization or permission checks, which could be exploited for file manipulation or directory traversal. The lack of vulnerability history might suggest it hasn't been widely targeted or analyzed, but the current code analysis reveals critical weaknesses that need immediate attention.

Key Concerns

  • Unescaped output (all 33 outputs)
  • Shortcode without capability checks
  • File operations without apparent checks
  • Missing nonce checks
Vulnerabilities
None known

NanTuki YiFy-Torrent Adder Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

NanTuki YiFy-Torrent Adder Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
33
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
2
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped33 total outputs
Attack Surface

NanTuki YiFy-Torrent Adder Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[yts] nantuki_yts.php:27
WordPress Hooks 1
actionadmin_menuyifyset.php:2
Maintenance & Trust

NanTuki YiFy-Torrent Adder Maintenance & Trust

Maintenance Signals

WordPress version tested4.0.38
Last updatedNov 14, 2014
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

NanTuki YiFy-Torrent Adder Developer Profile

Nazmul Alam

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect NanTuki YiFy-Torrent Adder

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

Shortcode Output
[yts id="ytsmovieid"]
FAQ

Frequently Asked Questions about NanTuki YiFy-Torrent Adder