HiiWaterwheel WordPress Plugin Security & Risk Analysis

wordpress.org/plugins/hiiwaterwheel

This plugin allows you create a basic waterwheel image carousel

10 active installs v0.0.5 PHP 7.0+ WP 4.0+ Updated Sep 20, 2018
carouselimageswaterwheel
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is HiiWaterwheel WordPress Plugin Safe to Use in 2026?

Generally Safe

Score 85/100

HiiWaterwheel WordPress Plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The plugin "hiiwaterwheel" v0.0.5 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of any registered CVEs, coupled with the fact that all identified SQL queries utilize prepared statements and no critical taint flows were detected, indicates good development practices. The plugin also avoids dangerous functions and file operations, further contributing to its security. However, there are areas for improvement. The lack of nonce checks and capability checks across all entry points, particularly the single shortcode, presents a potential risk. While the attack surface is small (1 entry point), it's entirely unprotected by these common security mechanisms. Additionally, 25% of output escaping is not properly handled, which could lead to cross-site scripting (XSS) vulnerabilities if the unescaped output contains user-supplied data. The bundled Select2 library, if outdated, could also introduce vulnerabilities not directly apparent in this analysis. Overall, while the plugin has a clean history and avoids common pitfalls like raw SQL, the lack of robust authentication and authorization on its entry point, and incomplete output escaping, are notable weaknesses that require attention.

Key Concerns

  • Missing nonce checks on entry points
  • Missing capability checks on entry points
  • Unescaped output detected
  • Bundled Select2 library (potential for outdated version)
Vulnerabilities
None known

HiiWaterwheel WordPress Plugin Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

HiiWaterwheel WordPress Plugin Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
3 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Select2

Output Escaping

75% escaped4 total outputs
Attack Surface

HiiWaterwheel WordPress Plugin Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[hiiww] includes\class-hiiwaterwheel-shortcodes.php:16
WordPress Hooks 19
filtermanage_waterwheel_posts_columnshiiwaterwheel-functions.php:16
actionmanage_waterwheel_posts_custom_columnhiiwaterwheel-functions.php:24
filterbody_classhiiwaterwheel-template.php:107
actionafter_switch_themehiiwaterwheel.php:112
actionafter_switch_themehiiwaterwheel.php:113
actionafter_switch_themehiiwaterwheel.php:114
actionafter_setup_themehiiwaterwheel.php:117
actionafter_setup_themehiiwaterwheel.php:118
actionwidget_inithiiwaterwheel.php:119
actionwp_enqueue_scriptshiiwaterwheel.php:120
actionadmin_inithiiwaterwheel.php:121
actionadmin_menuincludes\admin\class-hiiwaterwheel-admin.php:24
actionadmin_enqueue_scriptsincludes\admin\class-hiiwaterwheel-admin.php:25
actioncmb2_initincludes\admin\class-hiiwaterwheel-writepanels.php:40
actioninitincludes\class-hiiwaterwheel-ajax.php:13
actiontemplate_redirectincludes\class-hiiwaterwheel-ajax.php:14
actioninitincludes\class-hiiwaterwheel-post-types.php:40
actioninitincludes\class-hiiwaterwheel-post-types.php:41
filterrp4wp_get_templateincludes\class-hiiwaterwheel-post-types.php:44
Maintenance & Trust

HiiWaterwheel WordPress Plugin Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedSep 20, 2018
PHP min version7.0
Downloads1K

Community Trust

Rating80/100
Number of ratings1
Active installs10
Developer Profile

HiiWaterwheel WordPress Plugin Developer Profile

hiilite

2 plugins · 410 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect HiiWaterwheel WordPress Plugin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/hiiwaterwheel/assets/css/frontend.css/wp-content/plugins/hiiwaterwheel/assets/js/hiiwaterwheel-scripts.js/wp-content/plugins/hiiwaterwheel/assets/js/jquery-deserialize/jquery.deserialize.js
Script Paths
/wp-content/plugins/hiiwaterwheel/assets/js/hiiwaterwheel-scripts.js/wp-content/plugins/hiiwaterwheel/assets/js/jquery-deserialize/jquery.deserialize.js
Version Parameters
hiiwaterwheel/assets/css/frontend.css?ver=hiiwaterwheel/assets/js/hiiwaterwheel-scripts.js?ver=hiiwaterwheel/assets/js/jquery-deserialize/jquery.deserialize.js?ver=

HTML / DOM Fingerprints

CSS Classes
hiiwaterwheel-wrapper
JS Globals
HIIWATERWHEEL_VERSIONHIIWATERWHEEL_URLHIIWATERWHEEL_DIRhiiwaterwheel_admin_csshiiwaterwheel
Shortcode Output
<div class="hiiwaterwheel-wrapper">
FAQ

Frequently Asked Questions about HiiWaterwheel WordPress Plugin