Hover Effects – easily create any hover effect Security & Risk Analysis

wordpress.org/plugins/hover-effects

Hover Effect is easily applied to your own elements, modified or just used for inspiration.

8K active installs v2.1.3 PHP 7.4+ WP 4.3+ Updated Dec 2, 2025
button-hover-effectshover-animationshover-effectsimage-hover-effects
98
A · Safe
CVEs total2
Unpatched0
Last CVEJun 27, 2025
Safety Verdict

Is Hover Effects – easily create any hover effect Safe to Use in 2026?

Generally Safe

Score 98/100

Hover Effects – easily create any hover effect has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

2 known CVEsLast CVE: Jun 27, 2025Updated 5mo ago
Risk Assessment

The static analysis of "hover-effects" v2.1.3 shows a strong adherence to secure coding practices, with no identified attack surface, dangerous functions, or issues with SQL queries, output escaping, file operations, or external HTTP requests. Taint analysis also reveals no critical or high severity issues. This indicates the current version is well-sanitized from many common web vulnerabilities.

However, the plugin's vulnerability history presents a significant concern. It has a history of two medium severity vulnerabilities: SQL Injection and PHP Remote File Inclusion. While there are currently no unpatched CVEs, the existence of these past vulnerabilities, particularly those related to injection and file inclusion, suggests a recurring pattern of potential security weaknesses in the plugin's development. The most recent vulnerability was reported on June 27, 2025, which is quite recent and implies that developers may have struggled to fully eradicate these types of flaws.

In conclusion, while the current code analysis is reassuring, the plugin's past vulnerability landscape warrants caution. Users should be aware of the potential for similar issues to resurface, and developers should continue to focus on robust input validation and secure coding practices, particularly around handling user-supplied data and file operations, to prevent a recurrence of past vulnerabilities.

Key Concerns

  • Past medium severity SQL Injection vulnerabilities
  • Past medium severity RFI vulnerabilities
  • No nonce checks on any entry points
  • No capability checks on any entry points
Vulnerabilities
2 published

Hover Effects – easily create any hover effect Security Vulnerabilities

CVEs by Year

1 CVE in 2022
2022
1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2025-53258medium · 4.9Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Hover Effects <= 2.1.2 - Authenticated (Administrator+) SQL Injection

Jun 27, 2025 Patched in 2.1.3 (160d)
CVE-2022-29447medium · 6.8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')

Hover Effects – easily create any hover effect <= 2.1 - Authenticated Local File Inclusion

May 16, 2022 Patched in 2.1.1 (616d)
Version History

Hover Effects – easily create any hover effect Release Timeline

v2.1.3Current
v2.1.21 CVE
v2.1.11 CVE
Code Analysis
Analyzed Mar 16, 2026

Hover Effects – easily create any hover effect Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
38 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped38 total outputs
Attack Surface

Hover Effects – easily create any hover effect Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionadmin_menuhover-effects.php:47
actionwp_enqueue_scriptshover-effects.php:50
actionadmin_enqueue_scriptshover-effects.php:51
filterplugin_row_metahover-effects.php:54
filterplugin_action_linkshover-effects.php:55
actionadmin_menuincludes\class-wow-company.php:20
actionadmin_enqueue_scriptsincludes\class-wow-company.php:21
Maintenance & Trust

Hover Effects – easily create any hover effect Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 2, 2025
PHP min version7.4
Downloads73K

Community Trust

Rating96/100
Number of ratings17
Active installs8K
Developer Profile

Hover Effects – easily create any hover effect Developer Profile

Wow-Company

26 plugins · 98K total installs

76
trust score
Avg Security Score
95/100
Avg Patch Time
236 days
View full developer profile
Detection Fingerprints

How We Detect Hover Effects – easily create any hover effect

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/hover-effects/admin/css/style.css/wp-content/plugins/hover-effects/admin/js/script.js/wp-content/plugins/hover-effects/asset/css/hover.css
Script Paths
/wp-content/plugins/hover-effects/admin/js/script.js
Version Parameters
hover-effects/admin/css/style.css?ver=hover-effects/admin/js/script.js?ver=hover-effects/asset/css/hover.css?ver=hover-effects/includes/assets/css/style.css?ver=1.0hover-effects/includes/assets/css/admin.css?ver=1.0

HTML / DOM Fingerprints

CSS Classes
wow-company
Data Attributes
data-wow-company
JS Globals
wow_company_plugin
FAQ

Frequently Asked Questions about Hover Effects – easily create any hover effect