
Hao Image Box Security & Risk Analysis
wordpress.org/plugins/hao-image-boxwordpress的一个灯箱插件,简单配置易上手,自适应手机端。
Is Hao Image Box Safe to Use in 2026?
Generally Safe
Score 85/100Hao Image Box has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "hao-image-box" v1.0 plugin exhibits a seemingly strong security posture based on the provided static analysis. There are no identified dangerous functions, SQL injection vulnerabilities via prepared statements, file operations, or external HTTP requests. The absence of any recorded CVEs in its history further suggests a lack of publicly known security flaws. The total entry points are zero, and importantly, all identified entry points (if any existed) are reported as protected, implying a good practice in limiting the attack surface. However, a significant concern arises from the complete lack of nonce checks and capability checks. This indicates that even if entry points were present, there's no mechanism to verify user permissions or prevent cross-site request forgery (CSRF) attacks. Additionally, 50% of output escaping is a weakness; while not all outputs are unescaped, the presence of any unescaped output is a potential vector for cross-site scripting (XSS) vulnerabilities. The taint analysis showing zero flows is positive, but it relies on the completeness of the analysis itself.
Key Concerns
- Missing nonce checks
- Missing capability checks
- Half of outputs not properly escaped
Hao Image Box Security Vulnerabilities
Hao Image Box Code Analysis
Output Escaping
Hao Image Box Attack Surface
WordPress Hooks 4
Maintenance & Trust
Hao Image Box Maintenance & Trust
Maintenance Signals
Community Trust
Hao Image Box Alternatives
pixi Image Gallery
pixi-image-gallery
Enhance your Elementor page building experience with Filterable Gallery and Standard Image Gallery layout. Add powers to your page builder using our e …
ele Hover Addon
ele-hover-addon
Enhance your Elementor page building experience with 3+ creative Image Hover elements. Add powers to your page builder
Custom Alt Text for Elementor
custom-alt-text-for-elementor
Extends Elementor Image and Image Box widgets with custom alt text fields that support dynamic tags and shortcodes for better accessibility and SEO.
Extended Image Box Widget for Elementor
extended-image-box-widget-for-elementor
An enhanced Image Box widget for Elementor with independent links, button support, and flexible layout options.
Hao Image Box Developer Profile
1 plugin · 10 total installs
How We Detect Hao Image Box
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/hao-image-box/assets/css/imagelightbox.css/wp-content/plugins/hao-image-box/assets/js/imagelightbox.min.js/wp-content/plugins/hao-image-box/assets/js/imagelightbox.min.jshao-image-box/assets/css/imagelightbox.css?ver=hao-image-box/assets/js/imagelightbox.min.js?ver=HTML / DOM Fingerprints
data-hztjQuery