
xm Stilfinder Security & Risk Analysis
wordpress.org/plugins/xm-stilfinderCategorize Images and filter them in a front-end dialogue with form Submission. Uses formidable forms.
Is xm Stilfinder Safe to Use in 2026?
Generally Safe
Score 100/100xm Stilfinder has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "xm-stilfinder" v1.35 plugin demonstrates a strong security posture in several key areas. The static analysis reveals a complete absence of dangerous functions, file operations, and external HTTP requests, which are common vectors for exploitation. Furthermore, all SQL queries are properly prepared, and all output is correctly escaped, mitigating the risks of SQL injection and Cross-Site Scripting (XSS) respectively. The plugin also incorporates nonce checks and capability checks, suggesting an awareness of WordPress security best practices.
However, the analysis does identify one specific area of concern: one REST API route lacks permission callbacks. This means that this REST API endpoint is accessible without any authentication or authorization checks, potentially exposing it to unauthorized access or manipulation. While there are no recorded vulnerabilities or known CVEs for this plugin, this single unprotected entry point represents a potential security weakness that could be leveraged if an attacker discovers it and finds a way to exploit it.
In conclusion, "xm-stilfinder" v1.35 is generally well-secured, with strong coding practices observed in critical areas like SQL handling and output escaping. The lack of known vulnerabilities is a positive indicator. The primary weakness lies in the unprotected REST API route, which, though a single point, requires attention to ensure the plugin's overall security is maintained.
Key Concerns
- Unprotected REST API route
xm Stilfinder Security Vulnerabilities
xm Stilfinder Release Timeline
xm Stilfinder Code Analysis
SQL Query Safety
Output Escaping
xm Stilfinder Attack Surface
REST API Routes 1
Shortcodes 1
WordPress Hooks 10
Maintenance & Trust
xm Stilfinder Maintenance & Trust
Maintenance Signals
Community Trust
xm Stilfinder Alternatives
No alternatives data available yet.
xm Stilfinder Developer Profile
2 plugins · 10 total installs
How We Detect xm Stilfinder
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/xm-stilfinder/stilfinder-backend.js/wp-content/plugins/xm-stilfinder/stilfinder-frontend.js/wp-content/plugins/xm-stilfinder/stilfinder-admin.css/wp-content/plugins/xm-stilfinder/stilfinder-backend.js/wp-content/plugins/xm-stilfinder/stilfinder-frontend.jsxm-stilfinder/stilfinder-backend.js?ver=xm-stilfinder/stilfinder-frontend.js?ver=xm-stilfinder/stilfinder-admin.css?ver=HTML / DOM Fingerprints
stilfinder-backendstilfinder-admin-wrap<!-- .stilfinder-backend --><!-- END .stilfinder-backend --><!-- .stilfinder-admin-wrap --><!-- END .stilfinder-admin-wrap -->data-stilfinder-idwindow.xmstilfinder_vars/wp-json/xmstilfinder/v1/media<div class="stilfinder-frontend">