hiWeb Image Orient Security & Risk Analysis

wordpress.org/plugins/hiweb-image-orient

The plugin automatically turns photos taken on a smartphone, reading EXIF information from jpeg file. Плагин автоматически поворачивает фотографии, сд …

10 active installs v1.1 PHP + WP 4.0+ Updated Feb 23, 2018
automatic-photoautomatic-picturechange-images-anglechange-photo-anglefree-plugin
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is hiWeb Image Orient Safe to Use in 2026?

Generally Safe

Score 85/100

hiWeb Image Orient has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The "hiweb-image-orient" plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices regarding SQL queries, utilizing prepared statements exclusively, and it has no recorded history of vulnerabilities or known CVEs, suggesting a relatively stable and secure codebase to date. There are no instances of dangerous functions, file operations, external HTTP requests, or bundled libraries to raise immediate concerns. However, the plugin presents significant security weaknesses due to its unprotected entry points. The presence of two AJAX handlers without any authentication or capability checks creates a substantial attack surface. This means that any user, even unauthenticated ones, can trigger these AJAX actions, potentially leading to unintended consequences or exploitation if the handler logic is flawed. The absence of taint analysis results in the provided data means we cannot assess the risk of unsanitized input leading to vulnerabilities within these handlers. While the vulnerability history is clean, the unprotected AJAX handlers are a critical oversight that could be easily exploited if a vulnerability exists within them. The lack of nonce checks further exacerbates this risk. Therefore, while the plugin's core logic appears sound in certain areas, the exposed AJAX endpoints represent a critical vulnerability that must be addressed.

Key Concerns

  • Unprotected AJAX handlers (2)
  • Missing nonce checks on AJAX
  • Low output escaping coverage (25%)
Vulnerabilities
None known

hiWeb Image Orient Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

hiWeb Image Orient Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

25% escaped4 total outputs
Attack Surface
2 unprotected

hiWeb Image Orient Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_hiweb_image_orientinc\ajax.php:10
noprivwp_ajax_hiweb_image_orientinc\ajax.php:11
WordPress Hooks 3
actionadmin_menuinc\adminmenu.php:10
filterwp_handle_upload_prefilterinc\hooks.php:9
actionadmin_enqueue_scriptsinc\scripts.php:9
Maintenance & Trust

hiWeb Image Orient Maintenance & Trust

Maintenance Signals

WordPress version tested4.5.33
Last updatedFeb 23, 2018
PHP min version
Downloads1K

Community Trust

Rating60/100
Number of ratings2
Active installs10
Alternatives

hiWeb Image Orient Alternatives

No alternatives data available yet.

Developer Profile

hiWeb Image Orient Developer Profile

Den Media

9 plugins · 100 total installs

82
trust score
Avg Security Score
83/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect hiWeb Image Orient

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/hiweb-image-orient/css/backend.css/wp-content/plugins/hiweb-image-orient/js/hw-io-tool.js
Script Paths
/wp-content/plugins/hiweb-image-orient/js/hw-io-tool.js

HTML / DOM Fingerprints

CSS Classes
hw_io_message_done
JS Globals
hw_io_tool
FAQ

Frequently Asked Questions about hiWeb Image Orient