
hiWeb Core Security & Risk Analysis
wordpress.org/plugins/hiweb-coreThe plugin allows you to quickly create Web sites on WordPress, immediately unpack and activate the archives of favorite plug-ins, show common adminis …
Is hiWeb Core Safe to Use in 2026?
Generally Safe
Score 85/100hiWeb Core has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The hiweb-core plugin v1.4.4.3 exhibits a mixed security posture. While it has no recorded vulnerabilities (CVEs) and a seemingly limited attack surface in terms of exposed entry points (AJAX, REST API, shortcodes, cron), several concerning signals are present in its static analysis. The plugin utilizes dangerous functions such as shell_exec and exec, which can be exploited for remote code execution if not handled with extreme care and proper sanitization. Furthermore, a significant portion of its output is not properly escaped, potentially leading to cross-site scripting (XSS) vulnerabilities. The taint analysis indicates that all analyzed flows have unsanitized paths, though thankfully no critical or high severity issues were flagged in this specific analysis. The file operations count is high, which, combined with unsanitized paths, could be a vector for path traversal or arbitrary file read/write vulnerabilities if not properly secured. The plugin also has a limited number of nonce and capability checks relative to its total code signals, suggesting potential privilege escalation or unauthorized action risks. Overall, the lack of known vulnerabilities is positive, but the presence of dangerous functions, poor output escaping, and unsanitized paths in taint analysis present substantial risks that require diligent security practices to mitigate.
Key Concerns
- Dangerous functions (shell_exec, exec)
- Low percentage of properly escaped output
- All taint flows have unsanitized paths
- Limited nonce checks
- Limited capability checks
hiWeb Core Security Vulnerabilities
hiWeb Core Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
hiWeb Core Attack Surface
WordPress Hooks 47
Maintenance & Trust
hiWeb Core Maintenance & Trust
Maintenance Signals
Community Trust
hiWeb Core Alternatives
Stratum Widgets for Elementor
stratum
20+ Premium widgets for Elementor, including Advanced Slider, Instagram, Google Maps, Advanced Accordion, Post Grid.
Customized Recent Comments
customized-recent-comments
Display recent comments on your blog with complete control over the layout and format of comments.
Teamspeak 3 Widget for WordPress
teamspeak-3-viewer-plugin-for-wordpress-widget
Allows to show the Users and Channels of a Teamspeak3 as a Widget ( TS VIEWER )
Top Contributors
top-contributors
Display your top commenters or authors in a widget.
CGA Plugin Helper
cga-plugin-helper
This plugin will assist you in the installation of plugins. Choose from a curated list, manually search for plugins and export all active plugins.
hiWeb Core Developer Profile
9 plugins · 100 total installs
How We Detect hiWeb Core
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/hiweb-core/inc/hiweb-core-plugins.php/wp-content/plugins/hiweb-core/inc/settings.php/wp-content/plugins/hiweb-core/css/hiweb-core.css/wp-content/plugins/hiweb-core/css/hiweb-core-settings/hiweb-core-settings.css/wp-content/plugins/hiweb-core/js/hiweb-core.js/wp-content/plugins/hiweb-core/js/hiweb-core-wp/hiweb-core-wp.jshiweb-core.js?ver=hiweb-core.css?ver=HTML / DOM Fingerprints
hiweb-core-pluginshiweb-core-settingsEasy as pie Custom post metadata-hiweb-corehiweb