eHive Objects Tag Cloud widget Security & Risk Analysis

wordpress.org/plugins/ehive-objects-tag-cloud-widget

A widget plugin that allows you to embed a cloud of popular eHive tags on your website.

10 active installs v2.4.0 PHP 5.3+ WP 3.3.1+ Updated Sep 25, 2025
archivecollectionehivehistorymuseum
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is eHive Objects Tag Cloud widget Safe to Use in 2026?

Generally Safe

Score 100/100

eHive Objects Tag Cloud widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7mo ago
Risk Assessment

The overall security posture of the ehive-objects-tag-cloud-widget plugin appears to be a mixed bag, with some strengths but notable weaknesses identified in the static analysis. The absence of any known CVEs and the complete lack of vulnerability history is a positive sign, suggesting a history of stable and secure code. Furthermore, the plugin demonstrates good practices by utilizing prepared statements for all SQL queries and not making external HTTP requests, which are common vectors for vulnerabilities. However, the static analysis reveals significant concerns, particularly the complete lack of output escaping across all 20 identified output points. This means that any dynamic data displayed by the widget could be vulnerable to Cross-Site Scripting (XSS) attacks if not properly sanitized before being presented to the user. The plugin also lacks nonce checks and capability checks, which, combined with the zero unprotected entry points, suggests that either there are no entry points susceptible to unauthorized access or these checks are missing and the attack surface is currently minimal or zero. While the zero attack surface is ideal, the reliance on this absence for security rather than implementing proper checks is a concern. In conclusion, the plugin benefits from a clean vulnerability history and good SQL practices, but the pervasive lack of output escaping and the absence of authentication/authorization checks on its (currently zero) entry points present a significant risk that needs to be addressed.

Key Concerns

  • All outputs are unescaped
  • No nonce checks present
  • No capability checks present
Vulnerabilities
None known

eHive Objects Tag Cloud widget Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

eHive Objects Tag Cloud widget Release Timeline

v2.4.0Current
v2.3.1
v2.3.0
v2.1.1
Code Analysis
Analyzed Mar 16, 2026

eHive Objects Tag Cloud widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
20
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped20 total outputs
Attack Surface

eHive Objects Tag Cloud widget Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionwidgets_initEHiveObjectsTagCloud_Widget.php:28
Maintenance & Trust

eHive Objects Tag Cloud widget Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 25, 2025
PHP min version5.3
Downloads5K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

eHive Objects Tag Cloud widget Developer Profile

Vernon Systems Limited

11 plugins · 360 total installs

100
trust score
Avg Security Score
100/100
Avg Patch Time
5 days
View full developer profile
Detection Fingerprints

How We Detect eHive Objects Tag Cloud widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ehive-objects-tag-cloud-widget/eHiveObjectsTagCloud_Widget.css
Version Parameters
ehive-objects-tag-cloud-widget/eHiveObjectsTagCloud_Widget.css?ver=0.0.1

HTML / DOM Fingerprints

CSS Classes
ehive-tag-cloud-widgetehive-tag-1ehive-tag-2ehive-tag-3ehive-tag-4ehive-tag-5ehive-tag-6ehive-tag-7+3 more
FAQ

Frequently Asked Questions about eHive Objects Tag Cloud widget