
Action Hooks Security & Risk Analysis
wordpress.org/plugins/bkc-action-hooksAction Hooks will helps to add HTML markup on any action from Customizer with Live Preview.
Is Action Hooks Safe to Use in 2026?
Generally Safe
Score 85/100Action Hooks has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The bkc-action-hooks plugin, in version 1.0.0, demonstrates a generally strong security posture based on the provided static analysis. The plugin has a very small attack surface, with only one AJAX handler, and importantly, this handler is not exposed without authentication checks. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests are all positive indicators. Taint analysis shows no identified vulnerabilities, further reinforcing the impression of secure coding practices. The plugin also includes a nonce check, which is a fundamental security measure for AJAX actions. The vulnerability history being completely clear suggests a lack of past issues, indicating a potentially stable and well-maintained codebase.
However, the absence of capability checks on the single AJAX handler, despite the lack of explicit authentication check mentioned, is a minor concern. While the analysis states '0 without auth checks' for AJAX handlers, it's worth noting that proper capability checks are crucial for ensuring that only authorized users can trigger actions, even if the handler itself is not entirely public. The limited output escaping (67% properly escaped) means that there's a possibility of XSS vulnerabilities in the unescaped outputs, though the severity of these would depend on the context and the data being outputted. Overall, the plugin appears to be in good health, with only minor areas for improvement regarding explicit capability checks and ensuring all output is properly escaped.
Key Concerns
- Missing capability checks on AJAX handler
- Unescaped output detected
Action Hooks Security Vulnerabilities
Action Hooks Code Analysis
Output Escaping
Action Hooks Attack Surface
AJAX Handlers 1
WordPress Hooks 5
Maintenance & Trust
Action Hooks Maintenance & Trust
Maintenance Signals
Community Trust
Action Hooks Alternatives
Astra Theme Visual Hooks
astra-theme-visual-hooks
All hook locations in Astra...
WP Hooks Finder
wp-hooks-finder
Everything on WordPress depends on the action and filter hooks. And they are the backbone of WordPress. You can enhance or customize any WordPress fun …
Visual Hook Guide for Kadence
visual-hook-guide-for-kadence
Find Kadence action hooks quickly and easily by seeing their actual locations inside your Kadence theme.
FacetWP Manipulator
facetwp-manipulator
FacetWP Manipulator allows you to add code to specific FacetWP filters and Actions to manipulate functionality without hard coding it to the theme.
Hookie for Woocommerce
hookie-woocommerce
Enables specific WooCommerce hooks to get shown into the page dom [Extension of Hookie (Visual Hook Reference)].
Action Hooks Developer Profile
2 plugins · 20 total installs
How We Detect Action Hooks
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bkc-action-hooks/assets/customizer-script.js/wp-content/plugins/bkc-action-hooks/custom-control/repeater/repeater.js/wp-content/plugins/bkc-action-hooks/custom-control/repeater/repeater.cssassets/customizer-script.jscustom-control/repeater/repeater.jsbkc-action-hooks/assets/customizer-script.js?ver=bkc-action-hooks/custom-control/repeater/repeater.js?ver=bkc-action-hooks/custom-control/repeater/repeater.css?ver=HTML / DOM Fingerprints
bkc-repeater-wrapperbkc-repeater-fieldbkc-repeater-rowbkc-repeater-add-control-buttonbkc-repeater-remove-control-buttonbkc-repeater-collapseddata-fieldtypedata-iddata-input-typeactionHooksLocalizedbkcL10n