HostFact bestelformulier integratie Security & Risk Analysis

wordpress.org/plugins/hostfact-bestelformulier-integratie

Eenvoudige manier om het bestelformulier van HostFact in de Wordpress website te integreren.

200 active installs v1.3 PHP + WP 4.0+ Updated May 16, 2025
hostfactiframe-wrapper
99
A · Safe
CVEs total1
Unpatched0
Last CVEDec 11, 2024
Safety Verdict

Is HostFact bestelformulier integratie Safe to Use in 2026?

Generally Safe

Score 99/100

HostFact bestelformulier integratie has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Dec 11, 2024Updated 10mo ago
Risk Assessment

The "hostfact-bestelformulier-integratie" v1.3 plugin exhibits a mixed security posture. On the positive side, the static analysis reveals excellent adherence to secure coding practices. There are no detected dangerous functions, all SQL queries use prepared statements, and all output is properly escaped. Furthermore, there are no file operations or external HTTP requests, which generally reduces the attack surface. The absence of taint flows with unsanitized paths is also a strong indicator of secure input handling.

However, the plugin does present some concerning areas. The static analysis highlights a lack of any nonce or capability checks across its entry points, including its single shortcode. This means that actions triggered by the shortcode are not protected against unauthorized execution or CSRF attacks. The vulnerability history, while showing no currently unpatched issues, indicates a past medium-severity Cross-Site Scripting (XSS) vulnerability. The fact that this vulnerability was recently disclosed (2024-12-11) and is no longer present suggests that the developer actively patches issues, but the presence of XSS in the past warrants caution.

In conclusion, while the plugin demonstrates good fundamental coding practices regarding SQL and output handling, the complete absence of authorization checks on its sole entry point is a significant weakness. Combined with the past XSS vulnerability, this suggests a moderate risk, particularly if the shortcode performs sensitive operations that are not adequately protected by WordPress's built-in role management.

Key Concerns

  • No nonce checks on entry points
  • No capability checks on entry points
  • Past medium severity XSS vulnerability
Vulnerabilities
1

HostFact bestelformulier integratie Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-11413medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

HostFact bestelformulier integratie <= 1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

Dec 11, 2024 Patched in 1.2 (97d)
Code Analysis
Analyzed Mar 16, 2026

HostFact bestelformulier integratie Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped1 total outputs
Attack Surface

HostFact bestelformulier integratie Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[bestelformulier] hostfact-bestelformulier.php:15
WordPress Hooks 1
actionwp_enqueue_scriptshostfact-bestelformulier.php:12
Maintenance & Trust

HostFact bestelformulier integratie Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMay 16, 2025
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs200
Alternatives

HostFact bestelformulier integratie Alternatives

No alternatives data available yet.

Developer Profile

HostFact bestelformulier integratie Developer Profile

HostFact

1 plugin · 200 total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
97 days
View full developer profile
Detection Fingerprints

How We Detect HostFact bestelformulier integratie

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/hostfact-bestelformulier-integratie/hf-orderform.js
Script Paths
/wp-content/plugins/hostfact-bestelformulier-integratie/hf-orderform.js
Version Parameters
hostfact-bestelformulier-integratie/hf-orderform.js?ver=

HTML / DOM Fingerprints

CSS Classes
hf-orderform
Shortcode Output
<iframe src="" scrolling="no" class="hf-orderform" style="width:100%;border:0;overflow-y:hidden;"></iframe>
FAQ

Frequently Asked Questions about HostFact bestelformulier integratie