City Hive Security & Risk Analysis

wordpress.org/plugins/city-hive

City Hive partner program Wordpress widget

10 active installs v0.2.0 PHP + WP 3.1.0+ Updated Unknown
advertisingaffiliatecity-hivecityhivee-commerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is City Hive Safe to Use in 2026?

Generally Safe

Score 100/100

City Hive has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "city-hive" plugin version 0.2.0 exhibits a generally good security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events without authentication checks significantly limits the potential attack surface. The code also demonstrates good practices with 100% of SQL queries utilizing prepared statements and the presence of nonce and capability checks. However, a significant concern arises from the low percentage of properly escaped output (9%). This indicates a potential for cross-site scripting (XSS) vulnerabilities where user-supplied data, if not properly sanitized before being displayed, could be executed in a user's browser. While no taint flows or dangerous functions were identified in this analysis, the file operation detected warrants further investigation to ensure it is handled securely and doesn't introduce risks.

Key Concerns

  • Low percentage of properly escaped output
  • File operation detected without context
Vulnerabilities
None known

City Hive Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

City Hive Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
10
1 escaped
Nonce Checks
1
Capability Checks
2
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

9% escaped11 total outputs
Attack Surface

City Hive Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionwp_headcity-hive-header-loader.php:150
actionadmin_menucity-hive-settings-menu.php:3
actionadmin_initcity-hive-settings-menu.php:8
filtertitle_save_precity-hive-update-handler.php:43
actionadd_meta_boxescity-hive-widget.php:11
actionsave_postcity-hive-widget.php:140
actionadmin_enqueue_scriptscity-hive-widget.php:175
Maintenance & Trust

City Hive Maintenance & Trust

Maintenance Signals

WordPress version tested4.4.34
Last updatedUnknown
PHP min version
Downloads4K

Community Trust

Rating100/100
Number of ratings4
Active installs10
Developer Profile

City Hive Developer Profile

City Hive

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect City Hive

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/city-hive/css/typeahead.css/wp-content/plugins/city-hive/js/handlebars.js/wp-content/plugins/city-hive/js/producers.js/wp-content/plugins/city-hive/js/products.js/wp-content/plugins/city-hive/js/typeahead.bundle.min.js
Script Paths
/wp-content/plugins/city-hive/js/typeahead.bundle.min.js/wp-content/plugins/city-hive/js/handlebars.js/wp-content/plugins/city-hive/js/products.js/wp-content/plugins/city-hive/js/producers.js

HTML / DOM Fingerprints

CSS Classes
typeaheadtt-input
Data Attributes
city_hive_meta_box_noncecity_hive_products_hiddencity_hive_related_products_hiddencity_hive_producers_hiddencity_hive_noshow_products_checkbox
JS Globals
initCityHiveProducts
FAQ

Frequently Asked Questions about City Hive