
Hower effect for Links Security & Risk Analysis
wordpress.org/plugins/hover-effectHover effect plugin is to create hover effect for links and Link buttons
Is Hower effect for Links Safe to Use in 2026?
Generally Safe
Score 85/100Hower effect for Links has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'hover-effect' plugin version 1.0.1 exhibits a generally good security posture based on the provided static analysis. The absence of dangerous functions, use of prepared statements for all SQL queries, and lack of file operations or external HTTP requests are strong indicators of secure coding practices. Furthermore, the plugin has no recorded vulnerabilities, CVEs, or common vulnerability types, suggesting a history of stable and secure releases.
However, there are significant areas for concern. The most notable issue is that 100% of its outputs are not properly escaped. This represents a critical risk, as it makes the plugin highly susceptible to Cross-Site Scripting (XSS) attacks. An attacker could potentially inject malicious scripts through user-controlled input that is then rendered by the plugin without proper sanitization. The lack of any nonce or capability checks, while not directly leading to immediate vulnerabilities given the zero unprotected entry points, indicates a missed opportunity for robust access control and could become a risk if new entry points are introduced in the future without corresponding security measures.
In conclusion, while the plugin demonstrates strengths in preventing common vulnerabilities like SQL injection and avoiding dangerous functions, the complete lack of output escaping is a severe and critical flaw that exposes users to XSS. The absence of broader security checks also suggests room for improvement in defense-in-depth strategies. Addressing the unescaped output should be the highest priority.
Key Concerns
- 100% of outputs are not properly escaped
- No nonce checks present
- No capability checks present
Hower effect for Links Security Vulnerabilities
Hower effect for Links Release Timeline
Hower effect for Links Code Analysis
Output Escaping
Hower effect for Links Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
Hower effect for Links Maintenance & Trust
Maintenance Signals
Community Trust
Hower effect for Links Alternatives
No alternatives data available yet.
Hower effect for Links Developer Profile
1 plugin · 10 total installs
How We Detect Hower effect for Links
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/hover-effect/css/default.cssHTML / DOM Fingerprints
hoviconeffect-1class="hover effect type"hrefvalue="page or website url"<a href=><i class="hovicon effect-1 "></i></a>