DemandHub Security & Risk Analysis

wordpress.org/plugins/demandhub

Add and customize DemandHub's website widgets on your WordPress website

60 active installs v1.0.0 PHP + WP 4.7+ Updated Sep 5, 2025
chat-widgetonline-bookingreview-widgettextingwebchat
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is DemandHub Safe to Use in 2026?

Generally Safe

Score 100/100

DemandHub has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7mo ago
Risk Assessment

Based on the static analysis and vulnerability history, the "demandhub" plugin v1.0.0 appears to have a strong initial security posture. The absence of any detected attack surface points like unprotected AJAX handlers, REST API routes, shortcodes, or cron events is a significant positive. Furthermore, the code signals indicate robust practices, with no dangerous functions used, all SQL queries employing prepared statements, and all output properly escaped. The lack of file operations, external HTTP requests, and the absence of recorded vulnerabilities in its history further contribute to this positive assessment.

However, the complete absence of nonce checks and capability checks across all code signals raises a significant concern. While the current attack surface appears minimal, the lack of these fundamental security mechanisms means that any entry points that might be added in future versions, or that are not immediately apparent in this snapshot, would be entirely unprotected against common WordPress vulnerabilities like Cross-Site Request Forgery (CSRF). The taint analysis also reported zero flows, which is excellent, but it's important to remember that static analysis is not foolproof and might miss complex or logic-based vulnerabilities.

In conclusion, while "demandhub" v1.0.0 demonstrates excellent coding practices in many areas, the lack of nonce and capability checks represents a notable weakness that could expose the plugin to risks if its attack surface were to expand or if it interacts with other parts of WordPress in an unauthenticated manner. The current vulnerability history is clean, which is reassuring, but the foundational security measures for handling user input and actions are missing.

Key Concerns

  • No nonce checks
  • No capability checks
Vulnerabilities
None known

DemandHub Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

DemandHub Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
10 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped10 total outputs
Attack Surface

DemandHub Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionactivated_plugindemandhub.php:104
actiondeactivated_plugindemandhub.php:105
actionadmin_menudemandhub.php:328
actionadmin_noticesdemandhub.php:330
actionadmin_print_stylesdemandhub.php:335
actionadmin_post_demandhub_script_codedemandhub.php:337
actionwp_footerdemandhub.php:339
Maintenance & Trust

DemandHub Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 5, 2025
PHP min version
Downloads884

Community Trust

Rating0/100
Number of ratings0
Active installs60
Developer Profile

DemandHub Developer Profile

demandhub

1 plugin · 60 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect DemandHub

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/demandhub/assets/style.css

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about DemandHub