
Show Media Widget Security & Risk Analysis
wordpress.org/plugins/show-media-widget-pdf-supportDisplay media images or pdf documents in a widget filtered by categories
Is Show Media Widget Safe to Use in 2026?
Generally Safe
Score 85/100Show Media Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "show-media-widget-pdf-support" plugin version 1.0.9 exhibits a concerning security posture primarily due to its unprotected AJAX handlers. While the plugin demonstrates good practices by avoiding dangerous functions, SQL injection risks through prepared statements, and file operations, the lack of authentication on two AJAX entry points creates a significant attack surface. This means any unauthenticated user could potentially trigger these handlers, leading to unintended actions or information disclosure if not carefully secured within the handler itself.
The static analysis revealed no critical or high-severity taint flows, which is positive. However, the low percentage of properly escaped output (10%) suggests a risk of Cross-Site Scripting (XSS) vulnerabilities. While not explicitly detailed as a taint flow, unsafely rendered output can be a vector for attackers to inject malicious scripts. The absence of vulnerability history, including CVEs, is generally a good sign, indicating the plugin has not been publicly associated with known security flaws. This suggests a potentially stable codebase, but it doesn't negate the immediate risks identified in the current code analysis.
In conclusion, the plugin has strengths in its handling of SQL and avoiding common dangerous functions. However, the unprotected AJAX handlers represent a critical weakness that must be addressed. The low rate of output escaping also presents a significant, albeit less severe, risk. The lack of historical vulnerabilities is encouraging, but the current code analysis reveals immediate threats that overshadow this positive aspect.
Key Concerns
- Unprotected AJAX handlers
- Low percentage of properly escaped output
Show Media Widget Security Vulnerabilities
Show Media Widget Code Analysis
Output Escaping
Show Media Widget Attack Surface
AJAX Handlers 2
WordPress Hooks 3
Maintenance & Trust
Show Media Widget Maintenance & Trust
Maintenance Signals
Community Trust
Show Media Widget Alternatives
IGIT Posts Slider Widget
igit-posts-slider-widget
Widget Plugin allows you to embed posts into your sidebar category, tags. Also you can show latest posts,old posts and posts by any order you want in …
Nowy Widget for WordPress
nowy-widget
The Nowy Widget plugin allows you to create, manage, edit, and customize new Nowy app social content posts gallery layout.
Astra Widgets
astra-widgets
Quickest solution to add widgets like Address, Social Profiles and List icons on a website built with Astra.
Social Icons Widget & Block – Social Media Icons & Share Buttons
social-icons-widget-by-wpzoom
Social media icons plugin for WordPress - Add 400+ social icons and share buttons. Gutenberg block, widget & Elementor support. GDPR compliant.
Social Media Share Buttons & Social Sharing Icons
ultimate-social-media-icons
Share buttons and pop up share icons for social media sharing
Show Media Widget Developer Profile
3 plugins · 50 total installs
How We Detect Show Media Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/show-media-widget-pdf-support/mediawidget.css/wp-content/plugins/show-media-widget-pdf-support/mediawidget.js/wp-content/plugins/show-media-widget-pdf-support/mediawidget.jsshow-media-widget-pdf-support/mediawidget.css?ver=show-media-widget-pdf-support/mediawidget.js?ver=HTML / DOM Fingerprints
media-widget-postmedia-widget-post-defaultMedia Widgetdata-number<div class="media-widget-post media-widget-post-default"><a href="" target="_blank"></a>