X3P0: Media Data Security & Risk Analysis

wordpress.org/plugins/x3p0-media-data

Display image, audio, and video metadata fields—EXIF, ID3, and more—right inside the WordPress block editor, instantly and flexibly.

0 active installs v2.0.0 PHP 8.1+ WP 6.8+ Updated Feb 23, 2026
exifid3imagesmediametadata
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is X3P0: Media Data Safe to Use in 2026?

Generally Safe

Score 100/100

X3P0: Media Data has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The 'x3p0-media-data' v2.0.0 plugin exhibits a strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points, along with a complete lack of dangerous functions, raw SQL queries, file operations, and external HTTP requests, indicates a very small attack surface. The high percentage of properly escaped output (95%) and the use of prepared statements for all SQL queries are excellent security practices. The plugin's vulnerability history is also clean, with no recorded CVEs, further bolstering its security perception.

However, the static analysis reveals a complete absence of nonce checks and capability checks. While the plugin's current design might not expose vulnerabilities due to its limited entry points, this is a significant oversight. If the plugin were to be extended or its functionalities expanded in the future, the lack of these fundamental WordPress security mechanisms would create a substantial risk of various attacks, including CSRF and unauthorized data manipulation. The zero taint flows are positive but could be a reflection of the limited scope of the analysis or the plugin's simplicity.

In conclusion, 'x3p0-media-data' v2.0.0 is currently very secure due to its minimal design and adherence to good coding practices for data handling. Its strengths lie in its protected entry points and robust SQL handling. The primary weakness, and the most concerning aspect, is the complete omission of nonce and capability checks. While not an immediate exploitable vulnerability in its current state, it represents a significant potential risk for future development and a deviation from standard WordPress security best practices.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

X3P0: Media Data Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

X3P0: Media Data Release Timeline

v2.0.0Current
v1.0.0
Code Analysis
Analyzed Mar 17, 2026

X3P0: Media Data Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
20 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

95% escaped21 total outputs
Attack Surface

X3P0: Media Data Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionplugins_loadedplugin.php:30
actionplugins_loadedplugin.php:33
filterblock_bindings_supported_attributes_x3p0/media-datasrc\Block\BlockBindingsSupport.php:30
filterrender_block_contextsrc\Block\BlockBindingsSupport.php:35
actioninitsrc\Block\BlockRegistrar.php:39
Maintenance & Trust

X3P0: Media Data Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 23, 2026
PHP min version8.1
Downloads228

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

X3P0: Media Data Developer Profile

Justin Tadlock

34 plugins · 33K total installs

84
trust score
Avg Security Score
86/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect X3P0: Media Data

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/x3p0-media-data/public/blocks/index.js/wp-content/plugins/x3p0-media-data/public/blocks/style-index.css/wp-content/plugins/x3p0-media-data/public/blocks/render.php
Script Paths
/wp-content/plugins/x3p0-media-data/public/blocks/index.js

HTML / DOM Fingerprints

CSS Classes
wp-block-x3p0-media-datawp-block-x3p0-media-data-field
Data Attributes
data-type="attachment-id"data-label=""data-field="title"data-field="caption"data-field="description"data-field="filename"+28 more
JS Globals
wp.blocks.registerBlockType
FAQ

Frequently Asked Questions about X3P0: Media Data