
TraktTV WordPress Widget Security & Risk Analysis
wordpress.org/plugins/trakttv-widgetsShow what you watch to your visitors. Widget, that shows your last watched movies or TV show episodes from trakt.tv
Is TraktTV WordPress Widget Safe to Use in 2026?
Generally Safe
Score 85/100TraktTV WordPress Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of trakttv-widgets v1.4.1 reveals a generally good security posture in terms of attack surface and database interactions. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, which significantly limits the potential entry points for attackers. Furthermore, all SQL queries are correctly using prepared statements, mitigating the risk of SQL injection vulnerabilities. The absence of file operations and bundled libraries also reduces potential attack vectors.
However, there are notable areas of concern. The extremely low percentage (2%) of properly escaped output is a critical weakness, suggesting a high risk of Cross-Site Scripting (XSS) vulnerabilities. While the taint analysis reported no unsanitized flows, this could be due to the limited scope of the analysis or the absence of complex data manipulation chains that would be flagged. The lack of nonce checks and capability checks on the identified entry points (even if zero) represents a missed opportunity for basic security hardening, though their absence in this case is less impactful due to the zero attack surface. The single external HTTP request should be monitored for potential vulnerabilities if the external service is compromised.
The plugin's vulnerability history is clean, with no recorded CVEs. This, combined with the static analysis findings of no critical taint flows or dangerous functions, suggests that this version of the plugin has been relatively secure. However, the high risk of XSS due to poor output escaping remains a significant concern that overshadows the positive aspects. A comprehensive security audit focusing on output sanitization is strongly recommended.
Key Concerns
- Insufficient output escaping (2% proper)
- No nonce checks found
- No capability checks found
TraktTV WordPress Widget Security Vulnerabilities
TraktTV WordPress Widget Release Timeline
TraktTV WordPress Widget Code Analysis
Output Escaping
TraktTV WordPress Widget Attack Surface
WordPress Hooks 4
Maintenance & Trust
TraktTV WordPress Widget Maintenance & Trust
Maintenance Signals
Community Trust
TraktTV WordPress Widget Alternatives
MAS Videos
masvideos
MAS Videos is a free plugin that allows you to to create and list movies, videos and TV shows.
JustWatch – Partner Integrations
justwatch-partner-integrations
Connect your audience to the best streaming services worldwide.
iCheckMovies Widget
icheckmovies-widget
Looks cool to share your latest seen movies on your blog.
WP Filmweb Widget
wp-filmweb-widget
Shows basic user data from Filmweb.pl portal.
XTCZ Top Box Office
xtcz-top-box-office
Real time Weekend Box Office results on your blog.
TraktTV WordPress Widget Developer Profile
4 plugins · 40 total installs
How We Detect TraktTV WordPress Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/trakttv-widgets/assets/css/trakttv.cssHTML / DOM Fingerprints
metabox-holderpostboxhndleinside<!-- -- path definitions --><!-- -- activation, deactivation and uninstall --><!-- TODO: Clean seen cache --><!-- ############################################################################# -->+8 morename="paypal-trakttv"value="_donations"name="business"value="3KYX5TTQD5NWU"name="lc"value="US"+12 more