XTCZ Top Box Office Security & Risk Analysis

wordpress.org/plugins/xtcz-top-box-office

Real time Weekend Box Office results on your blog.

10 active installs v2.0 PHP + WP 3.6+ Updated Aug 26, 2015
bollywoodbox-officebox-office-widgethollywoodmovies
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is XTCZ Top Box Office Safe to Use in 2026?

Generally Safe

Score 85/100

XTCZ Top Box Office has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The plugin "xtcz-top-box-office" v2.0 exhibits a generally good security posture with no known vulnerabilities in its history and a promising lack of dangerous functions, SQL injection risks due to prepared statements, and file operations. The absence of taint analysis findings further suggests a low risk of common code injection vulnerabilities. However, there are significant concerns regarding output escaping, with only 7% of 56 outputs being properly escaped. This indicates a high potential for Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data could be rendered directly in the browser without proper sanitization, allowing attackers to inject malicious scripts. Furthermore, the plugin lacks nonce checks and capability checks, which are critical for preventing Cross-Site Request Forgery (CSRF) and unauthorized actions, especially for AJAX handlers and shortcodes. While the attack surface appears limited and all identified entry points are reported as unprotected (which is a contradiction, implying there are entry points but none have authentication checks applied), the lack of these fundamental security measures is a significant weakness.

Key Concerns

  • Low output escaping rate
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

XTCZ Top Box Office Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

XTCZ Top Box Office Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
52
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

7% escaped56 total outputs
Attack Surface

XTCZ Top Box Office Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[xtcz_bollywood_boxoffice] xtcz-bollywood-shortcode.php:4
[xtcz_topboxoffice] xtcz-shortcode.php:4
WordPress Hooks 6
actionadmin_menuxtcz-top-boxoffic-movies.php:251
actionadmin_initxtcz-top-boxoffic-movies.php:255
actionwp_enqueue_scriptsxtcz-top-boxoffic-movies.php:262
actionadmin_enqueue_scriptsxtcz-top-boxoffic-movies.php:268
actionwidgets_initxtcz-widgets-bollywood.php:97
actionwidgets_initxtcz-widgets.php:138
Maintenance & Trust

XTCZ Top Box Office Maintenance & Trust

Maintenance Signals

WordPress version tested4.3.34
Last updatedAug 26, 2015
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings4
Active installs10
Developer Profile

XTCZ Top Box Office Developer Profile

Harish Kumar

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect XTCZ Top Box Office

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/xtcz-top-box-office/css/style.css/wp-content/plugins/xtcz-top-box-office/js/script.js
Script Paths
/wp-content/plugins/xtcz-top-box-office/js/script.js
Version Parameters
xtcz-top-box-office/css/style.css?ver=xtcz-top-box-office/js/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
xtcz_topboxoffice
Data Attributes
xtcz_topboxoffice_options
Shortcode Output
[xtcz_topboxoffice][xtcz_bollywood_boxoffice]
FAQ

Frequently Asked Questions about XTCZ Top Box Office