
HiiWaterwheel WordPress Plugin Security & Risk Analysis
wordpress.org/plugins/hiiwaterwheelThis plugin allows you create a basic waterwheel image carousel
Is HiiWaterwheel WordPress Plugin Safe to Use in 2026?
Generally Safe
Score 85/100HiiWaterwheel WordPress Plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "hiiwaterwheel" v0.0.5 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of any registered CVEs, coupled with the fact that all identified SQL queries utilize prepared statements and no critical taint flows were detected, indicates good development practices. The plugin also avoids dangerous functions and file operations, further contributing to its security. However, there are areas for improvement. The lack of nonce checks and capability checks across all entry points, particularly the single shortcode, presents a potential risk. While the attack surface is small (1 entry point), it's entirely unprotected by these common security mechanisms. Additionally, 25% of output escaping is not properly handled, which could lead to cross-site scripting (XSS) vulnerabilities if the unescaped output contains user-supplied data. The bundled Select2 library, if outdated, could also introduce vulnerabilities not directly apparent in this analysis. Overall, while the plugin has a clean history and avoids common pitfalls like raw SQL, the lack of robust authentication and authorization on its entry point, and incomplete output escaping, are notable weaknesses that require attention.
Key Concerns
- Missing nonce checks on entry points
- Missing capability checks on entry points
- Unescaped output detected
- Bundled Select2 library (potential for outdated version)
HiiWaterwheel WordPress Plugin Security Vulnerabilities
HiiWaterwheel WordPress Plugin Code Analysis
Bundled Libraries
Output Escaping
HiiWaterwheel WordPress Plugin Attack Surface
Shortcodes 1
WordPress Hooks 19
Maintenance & Trust
HiiWaterwheel WordPress Plugin Maintenance & Trust
Maintenance Signals
Community Trust
HiiWaterwheel WordPress Plugin Alternatives
Product Gallery Slider, Additional Variation Images, Product Video, Product Image Zoom and Lightbox for WooCommerce – WooGallery
gallery-slider-for-woocommerce
🔥 All-in-One WooCommerce Product Image and Video Gallery Solution to Enhance Your Customers' Shopping Experience and Boost Sales Instantly! 🚀
Agnosia Bootstrap Carousel by AuSoft
agnosia-bootstrap-carousel
This plugin lets you use the [gallery] shortcode to show a Bootstrap Carousel.
WP Bootstrap Carousel
wp-bootstrap-carousel
A simple, straightforward implementation of the Twitter Bootstrap Carousel in WordPress.
Hybrid Slideshow
hybrid-slideshow
Hybrid Slideshow is a jQuery powered image slideshow with drag and drop image ordering. The slideshow can be inserted using a shortcode, widget, or ph …
WP Carousel
wp-carousel
WP Carousel is a plugin that allows you to add a carousel with posts, categories, tags, authors, pages, and much more. It is easy to install and use.
HiiWaterwheel WordPress Plugin Developer Profile
2 plugins · 410 total installs
How We Detect HiiWaterwheel WordPress Plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/hiiwaterwheel/assets/css/frontend.css/wp-content/plugins/hiiwaterwheel/assets/js/hiiwaterwheel-scripts.js/wp-content/plugins/hiiwaterwheel/assets/js/jquery-deserialize/jquery.deserialize.js/wp-content/plugins/hiiwaterwheel/assets/js/hiiwaterwheel-scripts.js/wp-content/plugins/hiiwaterwheel/assets/js/jquery-deserialize/jquery.deserialize.jshiiwaterwheel/assets/css/frontend.css?ver=hiiwaterwheel/assets/js/hiiwaterwheel-scripts.js?ver=hiiwaterwheel/assets/js/jquery-deserialize/jquery.deserialize.js?ver=HTML / DOM Fingerprints
hiiwaterwheel-wrapperHIIWATERWHEEL_VERSIONHIIWATERWHEEL_URLHIIWATERWHEEL_DIRhiiwaterwheel_admin_csshiiwaterwheel<div class="hiiwaterwheel-wrapper">