
All in All Image Hover Effect Security & Risk Analysis
wordpress.org/plugins/all-in-all-image-hover-effectAll in All Image Hover Effect is pure CSS image hover effects wordpress plugin.
Is All in All Image Hover Effect Safe to Use in 2026?
Generally Safe
Score 85/100All in All Image Hover Effect has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'all-in-all-image-hover-effect' plugin v1.0.1 presents a concerning security posture despite a clean vulnerability history. The static analysis reveals significant weaknesses, most notably two AJAX handlers that lack authentication checks, creating a substantial attack surface. Furthermore, the use of the `unserialize` function without proper validation is a critical red flag, as it can lead to Remote Code Execution (RCE) if an attacker can control the serialized data. The extremely low percentage of properly escaped output (3%) indicates a high likelihood of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into a user's browser.
While the plugin boasts no known CVEs and uses prepared statements for SQL queries, these positive aspects are overshadowed by the critical security flaws identified in the code. The absence of capability checks and the presence of unprotected entry points mean that unauthorized users could potentially exploit these vulnerabilities. The lack of taint analysis results for flows with unsanitized paths is not necessarily a sign of safety, but rather a limitation of the analysis performed, leaving potential risks undetected.
In conclusion, the plugin exhibits several critical security weaknesses that significantly elevate its risk profile. The unprotected AJAX handlers and the dangerous `unserialize` function are immediate concerns. Coupled with widespread output escaping deficiencies, this plugin poses a considerable threat to WordPress sites. Users are strongly advised to exercise extreme caution or avoid this plugin until these vulnerabilities are addressed.
Key Concerns
- Unprotected AJAX handlers
- Dangerous function unserialize used
- Low percentage of properly escaped output
- Zero capability checks
All in All Image Hover Effect Security Vulnerabilities
All in All Image Hover Effect Code Analysis
Dangerous Functions Found
Output Escaping
All in All Image Hover Effect Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 18
Maintenance & Trust
All in All Image Hover Effect Maintenance & Trust
Maintenance Signals
Community Trust
All in All Image Hover Effect Alternatives
Ultimate Hover Effects
ultimate-hover-effects
Ultimate Hover Effects WordPress Plugin is an impressive powerfull modern, yet stylish hover effects for image captions.
Image Hover Effects Ultimate
image-hover-effects-ultimate
Create stunning image hover effects like gallery, lightbox, comparison, or magnifier with 500+ modern, elegant, lightweight animations.
Carousel 3D Slider
carousel-3d-slider
Configure a Responsive 3D jQuery Carousel Slider and Insert it in any Page or Post as a Shortcode.
Animated Featured Image
animated-featured-image
Responsive Featured Image for Sidebar Widgets with CSS3 Animations and Styles
Image 3D Carousel
image-3d-carousel
Image 3D Carousel With Shortcode for WordPress.
All in All Image Hover Effect Developer Profile
1 plugin · 0 total installs
How We Detect All in All Image Hover Effect
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/all-in-all-image-hover-effect/css/animate.min.css/wp-content/plugins/all-in-all-image-hover-effect/css/bootstrap.min.css/wp-content/plugins/all-in-all-image-hover-effect/css/js_composer.min.css/wp-content/plugins/all-in-all-image-hover-effect/css/marvelous-hover.css/wp-content/plugins/all-in-all-image-hover-effect/css/style.css/wp-content/plugins/all-in-all-image-hover-effect/css/vc_addons_kit.css/wp-content/plugins/all-in-all-image-hover-effect/js/jquery-migrate.min.js/wp-content/plugins/all-in-all-image-hover-effect/js/main.min.js+2 more/wp-content/plugins/all-in-all-image-hover-effect/js/jquery-migrate.min.js/wp-content/plugins/all-in-all-image-hover-effect/js/main.min.js/wp-content/plugins/all-in-all-image-hover-effect/js/marvelous-hover.js/wp-content/plugins/all-in-all-image-hover-effect/js/scripts.jsHTML / DOM Fingerprints
aaihe-sectiondata-effectdata-hover-effectdata-hover-directionaaihe_config[aaihe_gallery][aaihe_element]