
WP Filmweb Widget Security & Risk Analysis
wordpress.org/plugins/wp-filmweb-widgetShows basic user data from Filmweb.pl portal.
Is WP Filmweb Widget Safe to Use in 2026?
Generally Safe
Score 85/100WP Filmweb Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-filmweb-widget plugin version 0.5 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices regarding SQL queries, with 100% of them utilizing prepared statements, significantly reducing the risk of SQL injection vulnerabilities. Furthermore, there are no recorded CVEs, suggesting a history of responsible development or a lack of targeted attacks. The absence of external HTTP requests and bundled libraries also simplifies the security landscape and reduces potential attack vectors.
However, several areas raise concerns. The most significant is the lack of output escaping, with only 6% of outputs being properly handled. This creates a substantial risk of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the website through user-generated content or plugin outputs. Additionally, the complete absence of nonce checks and capability checks on any entry points (AJAX, REST API, shortcodes, cron) is a critical oversight. This means that any functionality exposed by the plugin, even if not directly apparent in the static analysis as having an attack surface, could be triggered by unauthenticated or unauthorized users, leading to unintended actions or data manipulation.
In conclusion, while the plugin avoids common pitfalls like raw SQL and unpatched vulnerabilities, the severe lack of output escaping and authorization checks presents a significant risk. The plugin would benefit greatly from implementing robust input validation, output sanitization, and proper authentication/authorization mechanisms for all its functionalities to achieve a more secure state.
Key Concerns
- Low output escaping percentage
- Missing nonce checks on entry points
- Missing capability checks on entry points
WP Filmweb Widget Security Vulnerabilities
WP Filmweb Widget Release Timeline
WP Filmweb Widget Code Analysis
SQL Query Safety
Output Escaping
WP Filmweb Widget Attack Surface
WordPress Hooks 3
Maintenance & Trust
WP Filmweb Widget Maintenance & Trust
Maintenance Signals
Community Trust
WP Filmweb Widget Alternatives
Feeds for TikTok (TikTok feed, video, and gallery plugin)
feeds-for-tiktok
The best way to display TikTok videos on your WordPress website. Display clean, customizable, and responsive TikTok feeds from your TikTok account.
Melu Managed Live Chat
melu-live-chat
Melu is a managed live chat service that provides live chat software via this plugin, and highly trained professional operators that look after it for …
Multi Twitter Stream
multi-twitter-widget
A simple widget that displays only the most recent tweet from multiple accounts.
iCheckMovies Widget
icheckmovies-widget
Looks cool to share your latest seen movies on your blog.
IM WooCommerce My Account Widget
im-woocommerce-my-account-widget
This plugin adds a widget with customer account information to your WooCommerce shop.
WP Filmweb Widget Developer Profile
2 plugins · 20 total installs
How We Detect WP Filmweb Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-filmweb-widget/backend/css/style.css/wp-content/plugins/wp-filmweb-widget/backend/js/script.jswp-filmweb-widget/backend/css/style.css?ver=wp-filmweb-widget/backend/js/script.js?ver=HTML / DOM Fingerprints
filmweb-widget-userdata-username-positiondata-avatar-sizedata-top-countdata-top-labeldata-last-countdata-last-label