Exclusive Hover effects Security & Risk Analysis

wordpress.org/plugins/exclusive-hover-effects

Exclusive HOver effects have few hover effects on images,buttons for make your website stunning and beautiful

20 active installs v2.2.1 PHP + WP 3.0.1+ Updated Sep 20, 2016
css3-hover-effectseffects-wordpress-pluginhover-effectimage-effectsimage-hover
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Exclusive Hover effects Safe to Use in 2026?

Generally Safe

Score 85/100

Exclusive Hover effects has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The "exclusive-hover-effects" plugin v2.2.1 exhibits a mixed security posture. While it has no recorded vulnerability history, which is a positive indicator, the static analysis reveals several concerning practices. The presence of an unprotected AJAX handler significantly expands the attack surface, making it a primary concern. The taint analysis highlighting two flows with unsanitized paths, even without critical or high severity designations, suggests potential for vulnerabilities if these paths are triggered. Furthermore, the plugin uses the dangerous `create_function` and has a concerningly low percentage of properly escaped output, indicating a higher risk of cross-site scripting (XSS) vulnerabilities. The use of raw SQL queries without prepared statements is also a red flag for potential SQL injection risks. Despite the lack of known CVEs, these code-level issues point to potential weaknesses that could be exploited. The plugin demonstrates some good practices like nonce and capability checks, but these are overshadowed by the critical areas of concern regarding unprotected entry points and insecure coding practices.

Key Concerns

  • Unprotected AJAX handler
  • Taint flows with unsanitized paths
  • Use of dangerous function 'create_function'
  • Raw SQL queries without prepared statements
  • Low percentage of output escaping
Vulnerabilities
None known

Exclusive Hover effects Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Exclusive Hover effects Release Timeline

No version history available.
Code Analysis
Analyzed Mar 16, 2026

Exclusive Hover effects Code Analysis

Dangerous Functions
1
Raw SQL Queries
1
0 prepared
Unescaped Output
191
7 escaped
Nonce Checks
4
Capability Checks
8
File Operations
5
External Requests
1
Bundled Libraries
1

Dangerous Functions Found

create_functionadd_filter( 'wp_default_editor', create_function('', 'return "tinymce";') );framework\bootstrap.php:195

Bundled Libraries

Select2

SQL Query Safety

0% prepared1 total queries

Output Escaping

4% escaped198 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
vp_ajax_wrapper (framework\bootstrap.php:75)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Exclusive Hover effects Attack Surface

Entry Points2
Unprotected1

AJAX Handlers 1

authwp_ajax_vp_ajax_wrapperframework\bootstrap.php:71

Shortcodes 1

[ex_effects] effects-pro-admin\shortcode.php:723
WordPress Hooks 35
actionadmin_headeffects-pro-admin\icon.php:14
actionwp_enqueue_scriptsexclusive-hover-effects.php:27
actionwp_footerexclusive-hover-effects.php:39
actionwp_enqueue_scriptsexclusive-hover-effects.php:73
actioninitexclusive-hover-effects.php:78
actioninitexclusive-hover-effects.php:99
actionafter_setup_themeexclusive-hover-effects.php:189
actionafter_setup_themeframework\bootstrap.php:41
actiontgmpa_registerframework\bootstrap.php:47
actioninitframework\bootstrap.php:112
actioncurrent_screenframework\bootstrap.php:113
actionadmin_enqueue_scriptsframework\bootstrap.php:114
actioncurrent_screenframework\bootstrap.php:115
filterclean_urlframework\bootstrap.php:116
actionadmin_footerframework\bootstrap.php:161
filterwp_default_editorframework\bootstrap.php:195
actioninitframework\classes\metabox.php:43
actionvp_option_first_activationframework\classes\option.php:81
actionadmin_menuframework\classes\option.php:100
actionadmin_noticesframework\classes\option.php:162
actioncurrent_screenframework\classes\shortcodegenerator.php:47
actionadmin_footerframework\classes\shortcodegenerator.php:58
filtermce_external_pluginsframework\classes\shortcodegenerator.php:288
filtermce_buttonsframework\classes\shortcodegenerator.php:289
filterwp_fullscreen_buttonsframework\classes\shortcodegenerator.php:290
filteradmin_print_stylesframework\classes\shortcodegenerator.php:291
actionadmin_enqueue_scriptsframework\classes\wp\enqueuer.php:27
actionadmin_headframework\includes\wpalchemy\MetaBox.php:22
actionadmin_footerframework\includes\wpalchemy\MetaBox.php:24
actionadmin_initframework\includes\wpalchemy\MetaBox.php:506
actionimport_post_metaframework\includes\wpalchemy\MetaBox.php:509
filteroutputframework\includes\wpalchemy\MetaBox.php:569
actionsave_postframework\includes\wpalchemy\MetaBox.php:579
actionadmin_headframework\includes\wpalchemy\MetaBox.php:619
actionadmin_footerframework\includes\wpalchemy\MetaBox.php:621
Maintenance & Trust

Exclusive Hover effects Maintenance & Trust

Maintenance Signals

WordPress version tested4.6.30
Last updatedSep 20, 2016
PHP min version
Downloads4K

Community Trust

Rating40/100
Number of ratings1
Active installs20
Developer Profile

Exclusive Hover effects Developer Profile

Prince Chowdhury

2 plugins · 30 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Exclusive Hover effects

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/exclusive-hover-effects/css/extra.css/wp-content/plugins/exclusive-hover-effects/css/style3.css/wp-content/plugins/exclusive-hover-effects/css/style4.css/wp-content/plugins/exclusive-hover-effects/css/normalizes.css/wp-content/plugins/exclusive-hover-effects/css/style_common.css/wp-content/plugins/exclusive-hover-effects/css/font-awesome.min.css/wp-content/plugins/exclusive-hover-effects/js/jquery.reveal.js/wp-content/plugins/exclusive-hover-effects/js/js/modernizr-2.8.3.min.js+2 more
Script Paths
/wp-content/plugins/exclusive-hover-effects/js/jquery.reveal.js/wp-content/plugins/exclusive-hover-effects/js/js/modernizr-2.8.3.min.js/wp-content/plugins/exclusive-hover-effects/js/hover_pack.js/wp-content/plugins/exclusive-hover-effects/js/jquery-migrate-1.2.1.min.js

HTML / DOM Fingerprints

CSS Classes
exeffects
JS Globals
VP_EFFECTS_VERSIONVP_EFFECTS_URLVP_EFFECTS_DIRVP_EFFECTS_FILE
Shortcode Output
[ex eff=
FAQ

Frequently Asked Questions about Exclusive Hover effects