Central Hubb AdServer Client Security & Risk Analysis

wordpress.org/plugins/centralhubb-wp-adserver-client

The ideal plugin for stats, related posts, search engine optimization, social sharing, protection, backups, security, and more.

0 active installs v1.0 PHP 7.0+ WP 4.7+ Updated May 17, 2018
advertscentral-hubbimagesvideoswordpress-com
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Central Hubb AdServer Client Safe to Use in 2026?

Generally Safe

Score 85/100

Central Hubb AdServer Client has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The "centralhubb-wp-adserver-client" v1.0 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for SQL queries, making it resilient against SQL injection vulnerabilities. The plugin also shows a high percentage of properly escaped output and no file operations or dangerous function usage, which are strong indicators of secure coding. Furthermore, the absence of any recorded vulnerabilities, CVEs, or critical taint flows suggests a generally stable history.

However, there are notable concerns regarding the attack surface. The plugin exposes two REST API routes that lack permission callbacks, meaning they are accessible without proper authentication. This represents a significant security risk, as attackers could potentially interact with these endpoints to gain unauthorized access or trigger unintended actions. While there is one nonce check and two capability checks present, these are insufficient to protect the entirety of the exposed REST API endpoints.

In conclusion, while the plugin excels in certain secure coding practices like data sanitization and SQL handling, the unprotected REST API endpoints present a critical weakness. The lack of historical vulnerabilities is a positive sign, but it does not mitigate the immediate risk posed by the exposed entry points. The developer should prioritize implementing proper authorization checks for all REST API routes.

Key Concerns

  • REST API routes without permission callbacks
  • REST API routes without permission callbacks
Vulnerabilities
None known

Central Hubb AdServer Client Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Central Hubb AdServer Client Release Timeline

v1.1
Code Analysis
Analyzed Apr 16, 2026

Central Hubb AdServer Client Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
12 escaped
Nonce Checks
1
Capability Checks
2
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

92% escaped13 total outputs
Attack Surface
2 unprotected

Central Hubb AdServer Client Attack Surface

Entry Points4
Unprotected2

REST API Routes 2

GET/wp-json/v1.*classes/api.php:34
POST/wp-json/v1.*classes/api.php:39

Shortcodes 2

[central-hubb-image-playlist] classes/plugin.php:22
[central-hubb-video] classes/plugin.php:23
WordPress Hooks 6
actionrest_api_initclasses/api.php:33
actionadmin_menuclasses/plugin.php:19
actionwp_footerclasses/plugin.php:20
actionadmin_menuclasses/settings.php:22
actionadmin_initclasses/settings.php:23
actioninitindex.php:21
Maintenance & Trust

Central Hubb AdServer Client Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedMay 17, 2018
PHP min version7.0
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs0
Developer Profile

Central Hubb AdServer Client Developer Profile

centralhubb

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Central Hubb AdServer Client

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/centralhubb-wp-adserver-client/sdk/sdk.min.js
Script Paths
/wp-content/plugins/centralhubb-wp-adserver-client/sdk/sdk.min.js
Version Parameters
centralhubb_js1.0

HTML / DOM Fingerprints

CSS Classes
central-hubb-image-playlist
Data Attributes
data-iddata-auto_play
JS Globals
phpVars
REST Endpoints
/wp-json/v1/
Shortcode Output
[central-hubb-image-playlist[central-hubb-video
FAQ

Frequently Asked Questions about Central Hubb AdServer Client