Hao Image Box Security & Risk Analysis

wordpress.org/plugins/hao-image-box

wordpress的一个灯箱插件,简单配置易上手,自适应手机端。

10 active installs v1.0 PHP 5.6+ WP 5.2+ Updated Nov 16, 2019
image-boxwordpress-image-light-box
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Hao Image Box Safe to Use in 2026?

Generally Safe

Score 85/100

Hao Image Box has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The "hao-image-box" v1.0 plugin exhibits a seemingly strong security posture based on the provided static analysis. There are no identified dangerous functions, SQL injection vulnerabilities via prepared statements, file operations, or external HTTP requests. The absence of any recorded CVEs in its history further suggests a lack of publicly known security flaws. The total entry points are zero, and importantly, all identified entry points (if any existed) are reported as protected, implying a good practice in limiting the attack surface. However, a significant concern arises from the complete lack of nonce checks and capability checks. This indicates that even if entry points were present, there's no mechanism to verify user permissions or prevent cross-site request forgery (CSRF) attacks. Additionally, 50% of output escaping is a weakness; while not all outputs are unescaped, the presence of any unescaped output is a potential vector for cross-site scripting (XSS) vulnerabilities. The taint analysis showing zero flows is positive, but it relies on the completeness of the analysis itself.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
  • Half of outputs not properly escaped
Vulnerabilities
None known

Hao Image Box Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Hao Image Box Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

50% escaped4 total outputs
Attack Surface

Hao Image Box Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_menuinc\hao-image-setting.php:2
actionadmin_initinc\hao-image-setting.php:152
actionwp_enqueue_scriptsinc\hao-image-view.php:16
actionwp_footerinc\hao-image-view.php:72
Maintenance & Trust

Hao Image Box Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedNov 16, 2019
PHP min version5.6
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Hao Image Box Developer Profile

haozhuti2019

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Hao Image Box

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/hao-image-box/assets/css/imagelightbox.css/wp-content/plugins/hao-image-box/assets/js/imagelightbox.min.js
Script Paths
/wp-content/plugins/hao-image-box/assets/js/imagelightbox.min.js
Version Parameters
hao-image-box/assets/css/imagelightbox.css?ver=hao-image-box/assets/js/imagelightbox.min.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-hzt
JS Globals
jQuery
FAQ

Frequently Asked Questions about Hao Image Box