
HG3-Include Security & Risk Analysis
wordpress.org/plugins/hg3-includePlugin to include any code (html, php, javascript,...) directly into the WordPress editor.
Is HG3-Include Safe to Use in 2026?
Generally Safe
Score 85/100HG3-Include has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "hg3-include" v1.1 plugin demonstrates a generally good security posture based on the static analysis, with no dangerous functions, no SQL queries that are not prepared, and no file operations or external HTTP requests. The absence of known vulnerabilities further strengthens this positive outlook. However, there are significant areas of concern. The plugin fails to properly escape any of its outputs, presenting a high risk of Cross-Site Scripting (XSS) vulnerabilities. Additionally, the lack of nonce and capability checks on any entry points, including shortcodes, means that these functionalities are wide open to unauthorized access and manipulation. While the attack surface appears small, its unprotected nature is a critical weakness.
Key Concerns
- Output not properly escaped
- Missing nonce checks
- Missing capability checks
HG3-Include Security Vulnerabilities
HG3-Include Code Analysis
Output Escaping
HG3-Include Attack Surface
Shortcodes 2
WordPress Hooks 2
Maintenance & Trust
HG3-Include Maintenance & Trust
Maintenance Signals
Community Trust
HG3-Include Alternatives
Code Manager
code-manager
Write, test and deploy PHP, JavaScript, CSS and HTML code blocks from the WordPress dashboard.
Better Code Editor
better-code-editor
Make your editor better!
Code Revisions
code-revisions
WordPress native revisions for the theme and plugin editors.
WPCode – Insert Headers and Footers + Custom Code Snippets – WordPress Code Manager
insert-headers-and-footers
Easily add code snippets in WordPress. Insert header & footer scripts, add PHP code snippets with conditional logic, insert ads pixel code, and more.
Code Snippets
code-snippets
An easy, clean and simple way to enhance your site with code snippets.
HG3-Include Developer Profile
1 plugin · 10 total installs
How We Detect HG3-Include
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
ccc 26/06/11 -- 09:14 ------- osX garde les (, ne vire que la ) finale [hg3_include