
Blog Link Hover Preview Security & Risk Analysis
wordpress.org/plugins/blog-link-hover-previewAdds Wikipedia-style hover previews on internal post links as a pop-up card, showing the post title, excerpt, and a read more link.
Is Blog Link Hover Preview Safe to Use in 2026?
Generally Safe
Score 100/100Blog Link Hover Preview has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "blog-link-hover-preview" plugin v1.1.2 exhibits a strong security posture based on the provided static analysis. The plugin demonstrates excellent security practices by not utilizing dangerous functions, performing all SQL queries using prepared statements, and properly escaping all output. Furthermore, it implements a nonce check, which is crucial for securing AJAX actions. The absence of file operations and external HTTP requests further minimizes potential attack vectors. The vulnerability history shows no recorded CVEs, indicating a clean track record and suggesting that the developers have likely maintained good security standards over time.
While the static analysis reveals no critical or high-severity issues, a notable concern is the complete lack of capability checks on the two AJAX handlers. This means that any authenticated user, regardless of their role, can potentially trigger these handlers, which could lead to unintended actions if these handlers have any side effects. Although the current attack surface is small and there are no apparent taint flows with unsanitized paths, the absence of capability checks presents a weakness that could be exploited if the functionality of these AJAX handlers were to change or if a vulnerability were to be introduced in the future. Overall, the plugin is well-coded from a security perspective, but the lack of granular access control on its entry points is a point of concern.
Key Concerns
- AJAX handlers without capability checks
Blog Link Hover Preview Security Vulnerabilities
Blog Link Hover Preview Code Analysis
Output Escaping
Blog Link Hover Preview Attack Surface
AJAX Handlers 2
WordPress Hooks 4
Maintenance & Trust
Blog Link Hover Preview Maintenance & Trust
Maintenance Signals
Community Trust
Blog Link Hover Preview Alternatives
Internal Link Juicer: SEO Auto Linker for WordPress
internal-links
Improve your SEO and your user experience through internal linkbuilding. Automated links between your posts based on a smart keyword configuration.
Internal Links Manager
seo-automated-link-building
Boost your SEO and get better rankings with our automated link building plugin. With this plugin you can link any keyword to any URL - internal or ext …
Visual Link Preview
visual-link-preview
Display a fully customizable visual link preview for any internal or external link.
Autolinks Manager – SEO Auto Linker
daext-autolinks-manager
Automate your affiliate links, increase product page visits, link glossary keywords, and more with this advanced SEO auto-linker plugin.
Automatic Internal Links for SEO by Pagup
automatic-internal-links-for-seo
This fully automated plugin creates and boosts your internal linking in 2 clicks, using Yoast / Rank Math Focus keywords as anchor text for internal l …
Blog Link Hover Preview Developer Profile
2 plugins · 0 total installs
How We Detect Blog Link Hover Preview
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/blog-link-hover-preview/assets/hover.css/wp-content/plugins/blog-link-hover-preview/assets/hover.js/wp-content/plugins/blog-link-hover-preview/assets/hover.jsblog-link-hover-preview/assets/hover.css?ver=blog-link-hover-preview/assets/hover.js?ver=HTML / DOM Fingerprints
blhp-popupblhp-moredata-blhp-postBLHP/wp-json/wp/v2/posts