Hosted Content Importer (HCI) Security & Risk Analysis

wordpress.org/plugins/hosted-content-importer

Embeds a remotely hosted content. Contributors can edit a tiny piece of your blog text externally, without having ANY access to your website.

20 active installs v3.0.3 PHP + WP 4.0.0+ Updated Dec 5, 2020
cachedcontentembedexternalgist
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Hosted Content Importer (HCI) Safe to Use in 2026?

Generally Safe

Score 85/100

Hosted Content Importer (HCI) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The 'hosted-content-importer' v3.0.3 plugin exhibits a generally good security posture based on the provided static analysis and vulnerability history. The absence of recorded CVEs and critical taint flows is a significant positive indicator. The plugin also demonstrates good practices by implementing capability checks and a nonce check, and it has a limited attack surface with no unprotected entry points identified. However, there are areas for improvement that could further strengthen its security. Specifically, the 50% of SQL queries not using prepared statements pose a moderate risk of SQL injection. Additionally, the low percentage of properly escaped output (29%) indicates a significant risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data could be rendered without proper sanitization. The presence of file operations without explicit details on their handling also warrants caution. While the plugin is not currently associated with known vulnerabilities, the identified code signals suggest potential weaknesses that could be exploited if not addressed.

Key Concerns

  • SQL queries not using prepared statements
  • Low percentage of properly escaped output
Vulnerabilities
None known

Hosted Content Importer (HCI) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Hosted Content Importer (HCI) Release Timeline

v2.0.2
v2.0.1
v2.0.0
v1.0.0
Code Analysis
Analyzed Mar 16, 2026

Hosted Content Importer (HCI) Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
1 prepared
Unescaped Output
12
5 escaped
Nonce Checks
1
Capability Checks
2
File Operations
4
External Requests
1
Bundled Libraries
1

Bundled Libraries

TinyMCE

SQL Query Safety

50% prepared2 total queries

Output Escaping

29% escaped17 total outputs
Attack Surface

Hosted Content Importer (HCI) Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[hci] classes\hci\class.hosted_content_shortcode.inc.php:10
[third] classes\hci\class.hosted_content_shortcode.inc.php:11
WordPress Hooks 6
actionwp_enqueue_scriptsclasses\hci\class.hosted_content_shortcode.inc.php:13
actionadmin_menuclasses\hci\class.hosted_content_shortcode.inc.php:19
actionadmin_print_footer_scriptsclasses\hci\class.hosted_content_shortcode.inc.php:25
actioninitclasses\hci\class.hosted_content_shortcode.inc.php:26
filtermce_buttonsclasses\hci\class.hosted_content_shortcode.inc.php:200
filtermce_external_pluginsclasses\hci\class.hosted_content_shortcode.inc.php:201
Maintenance & Trust

Hosted Content Importer (HCI) Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedDec 5, 2020
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings2
Active installs20
Developer Profile

Hosted Content Importer (HCI) Developer Profile

Bimal Poudel

13 plugins · 840 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Hosted Content Importer (HCI)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/hosted-content-importer/css/hci.css

HTML / DOM Fingerprints

CSS Classes
hci-thirdhci-metahci-remote-content
Data Attributes
data-sourcedata-iddata-section
JS Globals
QTags
Shortcode Output
[third source="markdown" id="" section=""][third source="qr" id="url" section="internal"][third source="youtube" id="v00000000" section=""]
FAQ

Frequently Asked Questions about Hosted Content Importer (HCI)