
DemandHub Security & Risk Analysis
wordpress.org/plugins/demandhubAdd and customize DemandHub's website widgets on your WordPress website
Is DemandHub Safe to Use in 2026?
Generally Safe
Score 100/100DemandHub has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the static analysis and vulnerability history, the "demandhub" plugin v1.0.0 appears to have a strong initial security posture. The absence of any detected attack surface points like unprotected AJAX handlers, REST API routes, shortcodes, or cron events is a significant positive. Furthermore, the code signals indicate robust practices, with no dangerous functions used, all SQL queries employing prepared statements, and all output properly escaped. The lack of file operations, external HTTP requests, and the absence of recorded vulnerabilities in its history further contribute to this positive assessment.
However, the complete absence of nonce checks and capability checks across all code signals raises a significant concern. While the current attack surface appears minimal, the lack of these fundamental security mechanisms means that any entry points that might be added in future versions, or that are not immediately apparent in this snapshot, would be entirely unprotected against common WordPress vulnerabilities like Cross-Site Request Forgery (CSRF). The taint analysis also reported zero flows, which is excellent, but it's important to remember that static analysis is not foolproof and might miss complex or logic-based vulnerabilities.
In conclusion, while "demandhub" v1.0.0 demonstrates excellent coding practices in many areas, the lack of nonce and capability checks represents a notable weakness that could expose the plugin to risks if its attack surface were to expand or if it interacts with other parts of WordPress in an unauthenticated manner. The current vulnerability history is clean, which is reassuring, but the foundational security measures for handling user input and actions are missing.
Key Concerns
- No nonce checks
- No capability checks
DemandHub Security Vulnerabilities
DemandHub Code Analysis
Output Escaping
DemandHub Attack Surface
WordPress Hooks 7
Maintenance & Trust
DemandHub Maintenance & Trust
Maintenance Signals
Community Trust
DemandHub Alternatives
Podium
podium
Add and customize Podium's Web Suite tools to your WordPress website
Zidy_Chatbot
zidy-chatbot
This plugin allows Zidy users to install the generated Zidy chatbot code onto their WP site to communicate with their clients via SMS text messages.
eBanqo Widget
ebanqo-widget
eBanqo webchat plugin is a fast, convenient way to embed a customizable, real-time messaging platform on your website. Customizing an existing widget …
Tawk.To Live Chat
tawkto-live-chat
(OFFICIAL tawk.to plugin) Instantly chat with visitors on your website with the free tawk.to chat widget. Website: http://tawk.to
LeadConnector
leadconnector
LeadConnector: It helps you to add the LeadConnector chat widget and the LeadConnector funnel pages to your WordPress website.
DemandHub Developer Profile
1 plugin · 60 total installs
How We Detect DemandHub
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/demandhub/assets/style.css