
Hocus Pocus Buttons Security & Risk Analysis
wordpress.org/plugins/hocus-pocus-buttonsAutomagically show or don't show buttons/links for social bookmarking sites, depending on the sites the user has visited lately.
Is Hocus Pocus Buttons Safe to Use in 2026?
Generally Safe
Score 85/100Hocus Pocus Buttons has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "hocus-pocus-buttons" plugin v0.5 exhibits a strong adherence to some fundamental security practices. The static analysis reveals no direct attack surface through AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, the code signals indicate an absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests. Taint analysis shows no identified flows, suggesting no immediate data injection risks. The plugin also has no recorded vulnerability history, which is a positive indicator of past stability.
However, a significant concern arises from the complete lack of output escaping. With three identified output points, the fact that none are properly escaped presents a substantial Cross-Site Scripting (XSS) risk. Any data displayed by this plugin without proper sanitization could potentially be exploited. Additionally, the absence of nonce checks and capability checks, while not directly exploitable given the lack of exposed entry points, represents a missed opportunity to build in defense-in-depth and could become a problem if future updates introduce new functionalities without addressing these checks.
In conclusion, while the plugin's current attack surface is minimal and it lacks known vulnerabilities, the critical deficiency in output escaping poses a tangible risk. The absence of nonce and capability checks, though not a direct vulnerability in this version, points to potential areas for improvement in overall security hardening. Developers should prioritize addressing the unescaped outputs.
Key Concerns
- Unescaped output detected
- Missing nonce checks
- Missing capability checks
Hocus Pocus Buttons Security Vulnerabilities
Hocus Pocus Buttons Code Analysis
Output Escaping
Hocus Pocus Buttons Attack Surface
WordPress Hooks 1
Maintenance & Trust
Hocus Pocus Buttons Maintenance & Trust
Maintenance Signals
Community Trust
Hocus Pocus Buttons Alternatives
Fuse Social Floating Sidebar
fuse-social-floating-sidebar
This plugin allows you to add social media floating sidebar icons connected with your social media profiles.
RaraTheme Companion
raratheme-companion
23 extremely useful custom widgets to create an engaging website.
Social Media Icon Widget
new-social-media-widget
Add social media icon links to your sidebar with customizable styles, colors, hover effects, and animations.
More Widgets
more-widgets
The More Widgets plugin adds extra widgets to use with your widgetized areas within your WordPress site. Use this plugin instead of built-in theme wid …
Flare
flare
Flare is a simple yet eye-catching social sharing bar that gets you followed and lets your content get shared via posts, pages, and media types.
Hocus Pocus Buttons Developer Profile
1 plugin · 10 total installs
How We Detect Hocus Pocus Buttons
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
hp_buttonshp_buttons_css_defaulthp_buttons_css_blockhp_buttons_css_imagestheurlthetitlemode+4 more