Hide WP Security & Risk Analysis

wordpress.org/plugins/hide-wp

Hide WP

100 active installs v1.0.5 PHP + WP 4.0+ Updated Mar 12, 2016
antyspamprotectsave-resourcessecurityspam
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Hide WP Safe to Use in 2026?

Generally Safe

Score 85/100

Hide WP has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The "hide-wp" plugin v1.0.5 exhibits a mixed security posture. On the positive side, there are no known vulnerabilities (CVEs) associated with this plugin, and the static analysis shows no critical or high severity taint flows, dangerous functions, or raw SQL queries. The presence of a nonce check and 100% use of prepared statements for SQL are good security practices.

However, a significant concern arises from the complete lack of proper output escaping across all identified outputs. This indicates a high risk of cross-site scripting (XSS) vulnerabilities. If any user-supplied data or dynamic content is outputted without sanitization, it could be exploited by attackers to inject malicious scripts. Additionally, the absence of capability checks on any entry points, though the attack surface is currently zero, means that if new entry points are added in the future without proper authorization checks, they could be exposed.

Given the clean vulnerability history, it's possible this plugin has not been extensively tested or that previous versions were secure. The critical weakness is the unescaped output, which significantly elevates the risk profile despite the absence of other major flaws. Users should be aware of the potential for XSS attacks.

Key Concerns

  • No proper output escaping
  • No capability checks on entry points
Vulnerabilities
None known

Hide WP Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Hide WP Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
36
0 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped36 total outputs
Attack Surface

Hide WP Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 44
actionadmin_menuhide-wp-admin.php:12
filtermod_rewrite_ruleshide-wp-admin.php:13
actioninithide-wp.php:26
actionadmin_inithide-wp.php:27
filtersite_urlhide-wp.php:28
filterupload_dirhide-wp.php:29
filterplugins_urlhide-wp.php:30
filtertemplate_directory_urihide-wp.php:31
filterstylesheet_urihide-wp.php:32
filterstylesheet_directory_urihide-wp.php:33
filterincludes_urlhide-wp.php:34
filterwp_admin_csshide-wp.php:35
filteradmin_urlhide-wp.php:36
filterscript_loader_srchide-wp.php:37
filterstyle_loader_srchide-wp.php:38
filterlogin_urlhide-wp.php:39
filterregister_urlhide-wp.php:40
filterlostpassword_urlhide-wp.php:41
filterlogout_urlhide-wp.php:42
filtertheme_root_urihide-wp.php:43
filterlogout_redirecthide-wp.php:44
filterwp_redirecthide-wp.php:45
actionauth_redirecthide-wp.php:46
actionset_logged_in_cookiehide-wp.php:47
actionset_auth_cookiehide-wp.php:48
actionclear_auth_cookiehide-wp.php:49
filterpost_linkhide-wp.php:50
filterpost_type_linkhide-wp.php:51
filterpage_linkhide-wp.php:52
filterterm_linkhide-wp.php:53
filterbloginfo_urlhide-wp.php:54
filtercron_requesthide-wp.php:55
filterget_the_generator_htmlhide-wp.php:57
filterget_the_generator_xhtmlhide-wp.php:58
filterget_the_generator_atomhide-wp.php:59
filterget_the_generator_rss2hide-wp.php:60
filterget_the_generator_rdfhide-wp.php:61
filterget_the_generator_commenthide-wp.php:62
filterget_the_generator_exporthide-wp.php:63
filterwp_headershide-wp.php:65
actionactivated_pluginhide-wp.php:67
actiondeactivated_pluginhide-wp.php:68
actionafter_switch_themehide-wp.php:69
filterw3tc_can_print_commenthide-wp.php:74
Maintenance & Trust

Hide WP Maintenance & Trust

Maintenance Signals

WordPress version tested4.4.34
Last updatedMar 12, 2016
PHP min version
Downloads12K

Community Trust

Rating58/100
Number of ratings17
Active installs100
Developer Profile

Hide WP Developer Profile

kursorA

2 plugins · 130 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Hide WP

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/hide-wp/hide-wp.css/wp-content/plugins/hide-wp/hide-wp.js
Script Paths
/wp-content/plugins/hide-wp/hide-wp.js
Version Parameters
hide-wp/style.css?ver=hide-wp/hide-wp.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Hide WP