Image Hover Effects Widgets Security & Risk Analysis

wordpress.org/plugins/egw-widgets-hover-effects

A simple widget that makes it a breeze to add images,Content, And CSS3 Hover Animation.

100 active installs v2.1 PHP + WP 3.5+ Updated Dec 7, 2016
colorfulcss3-image-hoverhover-effectstext-effectwidget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Image Hover Effects Widgets Safe to Use in 2026?

Generally Safe

Score 85/100

Image Hover Effects Widgets has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The "egw-widgets-hover-effects" v2.1 plugin exhibits a generally strong security posture based on the provided static analysis. The complete absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface. Furthermore, the code signals indicate a clean codebase with no dangerous functions, no direct SQL queries (all use prepared statements), no file operations, and no external HTTP requests. This suggests a thoughtful approach to development with security in mind, particularly regarding common injection vulnerabilities.

However, a notable concern arises from the output escaping. With 107 total outputs and only 35% properly escaped, there is a significant risk of Cross-Site Scripting (XSS) vulnerabilities. Attackers could potentially inject malicious scripts through user-controlled data that is not adequately sanitized before being displayed on the frontend. The lack of nonce checks and capability checks on any potential entry points, while currently non-existent, would become a critical issue if any were introduced in future versions without proper security measures.

The vulnerability history is also a positive indicator, showing no known CVEs. This suggests that the plugin has either been well-developed or has a history of timely patching. In conclusion, while the plugin is currently strong due to its limited attack surface and clean codebase regarding common injection vectors, the significant number of unescaped outputs presents a clear and present danger of XSS vulnerabilities that needs immediate attention.

Key Concerns

  • Significant amount of unescaped output
Vulnerabilities
None known

Image Hover Effects Widgets Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Image Hover Effects Widgets Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
70
37 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

35% escaped107 total outputs
Attack Surface

Image Hover Effects Widgets Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_enqueue_scriptsegwHoverEffects.php:20
actionwidgets_initegwHoverEffects.php:21
actionwp_enqueue_scriptsegwHoverEffects.php:22
actionplugins_loadedegwHoverEffects.php:23
Maintenance & Trust

Image Hover Effects Widgets Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.32
Last updatedDec 7, 2016
PHP min version
Downloads15K

Community Trust

Rating42/100
Number of ratings9
Active installs100
Developer Profile

Image Hover Effects Widgets Developer Profile

aThemeArt Translations

4 plugins · 2K total installs

74
trust score
Avg Security Score
71/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Image Hover Effects Widgets

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/egw-widgets-hover-effects/assets/css/front-end.css/wp-content/plugins/egw-widgets-hover-effects/assets/js/colpick.js/wp-content/plugins/egw-widgets-hover-effects/assets/js/back-end.js/wp-content/plugins/egw-widgets-hover-effects/assets/css/back-end.css/wp-content/plugins/egw-widgets-hover-effects/assets/css/colpick.css
Script Paths
/wp-content/plugins/egw-widgets-hover-effects/assets/js/colpick.js/wp-content/plugins/egw-widgets-hover-effects/assets/js/back-end.js
Version Parameters
egw-widgets-hover-effects/assets/css/front-end.css?ver=egw-widgets-hover-effects/assets/js/colpick.js?ver=egw-widgets-hover-effects/assets/js/back-end.js?ver=egw-widgets-hover-effects/assets/css/back-end.css?ver=egw-widgets-hover-effects/assets/css/colpick.css?ver=

HTML / DOM Fingerprints

CSS Classes
egw-hover-effect-wrap
Data Attributes
data-fontfamilydata-fontsizedata-textcolordata-textbgcolordata-bordercolordata-borderwidth+8 more
JS Globals
objectL10n
FAQ

Frequently Asked Questions about Image Hover Effects Widgets