Anything for Hire Security & Risk Analysis

wordpress.org/plugins/anything-for-hire

Anything For Hire widget to be added on a wordpress site, so your website visitors can make use of our powerful free booking system and as a partner y …

0 active installs v1.0 PHP 5.2.4+ WP 4.9.6+ Updated Jun 29, 2018
anything-for-hireanything-for-hire-partner-widgetanything-for-hire-plugin
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Anything for Hire Safe to Use in 2026?

Generally Safe

Score 85/100

Anything for Hire has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The "anything-for-hire" v1.0 plugin exhibits a seemingly strong security posture based on the provided static analysis. There are no identified entry points (AJAX, REST API, shortcodes, cron events) that are unprotected, which is a significant positive. The code also shows no signs of dangerous functions, file operations, or external HTTP requests, further contributing to a reduced attack surface. Notably, all SQL queries are prepared, and there are no recorded vulnerabilities in its history. This suggests a developer who is mindful of common security pitfalls.

However, there are areas for concern. The plugin has a 50% rate of unescaped output, meaning half of its total outputs are not properly sanitized. This could lead to cross-site scripting (XSS) vulnerabilities if malicious input is processed and then displayed without proper escaping. Additionally, the absence of any identified nonce checks or capability checks on potential entry points (though none were found in this analysis) is a potential weakness. While the current analysis shows no unprotected entry points, if any were introduced in future versions or if the analysis missed something, the lack of these fundamental security measures would be a critical oversight. The lack of taint analysis data also prevents a complete understanding of data flow security.

In conclusion, the plugin has a good foundation with no critical static analysis findings and no historical vulnerabilities. The main weakness lies in the unescaped output. The absence of nonce and capability checks, while not an immediate critical flaw given the lack of entry points, represents a gap in robust security practices that should be addressed. Future development should prioritize proper output escaping for all data and ensure robust authorization checks if any entry points are ever implemented.

Key Concerns

  • Unescaped output detected
  • No nonce checks implemented
  • No capability checks implemented
Vulnerabilities
None known

Anything for Hire Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Anything for Hire Release Timeline

No version history available.
Code Analysis
Analyzed Mar 17, 2026

Anything for Hire Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

50% escaped4 total outputs
Attack Surface

Anything for Hire Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_menuindex.php:18
actionadmin_initindex.php:27
actionwp_footerindex.php:58
Maintenance & Trust

Anything for Hire Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedJun 29, 2018
PHP min version5.2.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Alternatives

Anything for Hire Alternatives

No alternatives data available yet.

Developer Profile

Anything for Hire Developer Profile

MOBO

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Anything for Hire

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/anything-for-hire/favicon.png/wp-content/plugins/anything-for-hire/logo.png

HTML / DOM Fingerprints

CSS Classes
wrap
Data Attributes
name="afhpartnerid"name="widget-location"value="left"value="right"value="bottom-left"value="bottom-right"
JS Globals
localStorage.setItem('afhid'localStorage.setItem('widget-location'
FAQ

Frequently Asked Questions about Anything for Hire