
HMH Footer Builder For Elementor Security & Risk Analysis
wordpress.org/plugins/hmh-footer-builder-for-elementorHMH Footer Builder For Elementor - Easy way to create any footers you can imagine.
Is HMH Footer Builder For Elementor Safe to Use in 2026?
Use With Caution
Score 64/100HMH Footer Builder For Elementor has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "hmh-footer-builder-for-elementor" plugin v1.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices by implementing nonce checks and capability checks for its entry points, and all SQL queries utilize prepared statements. The taint analysis shows no critical or high severity unsanitized flows, and a high percentage of output is properly escaped, suggesting an effort to prevent common injection vulnerabilities.
However, significant concerns arise from the presence of the `unserialize` function, which is inherently dangerous if not handled with extreme care and input validation. While the static analysis did not reveal specific unsanitized `unserialize` usage, its mere presence introduces a potential risk. Furthermore, the plugin has a history of known vulnerabilities, with one medium severity Cross-Site Scripting (XSS) vulnerability being currently unpatched. This indicates a potential pattern of security weaknesses that require diligent maintenance and prompt patching.
In conclusion, while the plugin has implemented some robust security measures, the presence of `unserialize` and an unpatched medium-severity vulnerability are notable weaknesses. The plugin's overall security is bolstered by its protected entry points and SQL practices, but these strengths are somewhat undermined by the identified historical and potentially exploitable code constructs. Continuous monitoring and prompt remediation of identified vulnerabilities are crucial for maintaining a secure environment.
Key Concerns
- Unpatched CVE
- Dangerous function detected (unserialize)
HMH Footer Builder For Elementor Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
HMH Footer Builder For Elementor <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
HMH Footer Builder For Elementor Code Analysis
Dangerous Functions Found
Bundled Libraries
Output Escaping
Data Flow Analysis
HMH Footer Builder For Elementor Attack Surface
AJAX Handlers 2
WordPress Hooks 57
Maintenance & Trust
HMH Footer Builder For Elementor Maintenance & Trust
Maintenance Signals
Community Trust
HMH Footer Builder For Elementor Alternatives
HMH Footer Builder For Elementor Developer Profile
2 plugins · 10 total installs
How We Detect HMH Footer Builder For Elementor
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/hmh-footer-builder-for-elementor/assets/admin/css/admin.css/wp-content/plugins/hmh-footer-builder-for-elementor/assets/css/bbfb.css/wp-content/plugins/hmh-footer-builder-for-elementor/assets/js/script.js/wp-content/plugins/hmh-footer-builder-for-elementor/assets/js/script.jshmh-footer-builder-for-elementor/assets/admin/css/admin.css?ver=hmh-footer-builder-for-elementor/assets/css/bbfb.css?ver=hmh-footer-builder-for-elementor/assets/js/script.js?ver=HTML / DOM Fingerprints
bb-footer-insideid="bb-footer-inside-class="bb-footer-inside"[bbfb_menus][bbfb_instagram][bbfb_social]