
Hover Pin-It Security & Risk Analysis
wordpress.org/plugins/hover-pin-itAdds a Pinterest "Pin It" button to images on your site, with eye catching hover effects.
Is Hover Pin-It Safe to Use in 2026?
Generally Safe
Score 85/100Hover Pin-It has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "hover-pin-it" plugin version 1.1 presents a mixed security posture. On the positive side, the plugin demonstrates good practices by utilizing prepared statements for all SQL queries and has no recorded vulnerability history, suggesting a generally well-maintained codebase. The attack surface, consisting of two shortcodes, is relatively small and, importantly, appears to lack direct unprotected entry points based on the static analysis. There are also no critical code signals like dangerous functions, file operations, or external HTTP requests, and the taint analysis found no issues, which are all favorable indicators.
However, a significant concern arises from the complete lack of output escaping. With four identified output points and none being properly escaped, this creates a high risk for Cross-Site Scripting (XSS) vulnerabilities. Attackers could potentially inject malicious scripts through user-supplied data that is then displayed on the website. Additionally, the absence of nonce checks and capability checks, while not directly tied to an attack vector in this specific analysis, indicates a potential for privilege escalation or unauthorized actions if the plugin were to evolve or interact with more sensitive functionalities in the future. The overall conclusion is that while the plugin avoids common pitfalls like raw SQL and known vulnerabilities, the critical lack of output escaping renders it susceptible to XSS attacks, demanding immediate attention.
Key Concerns
- 0% output escaping
- 0 nonce checks
- 0 capability checks
Hover Pin-It Security Vulnerabilities
Hover Pin-It Code Analysis
Output Escaping
Hover Pin-It Attack Surface
Shortcodes 2
WordPress Hooks 6
Maintenance & Trust
Hover Pin-It Maintenance & Trust
Maintenance Signals
Community Trust
Hover Pin-It Alternatives
Simple Pin It Button
simple-pin-it-button
Adds a "Pin it" button over images on hover with customizable options.
PinOperator Pinterest Pin It Button on Images
pinoperator-pinterest-pin-it-button-on-images
Adds a "Save to Pinterest" button to images in your WordPress posts and pages, making it easy for users to share your content on Pinterest.
Share Theme Plugin
share-theme
This is a extension for Share Theme
Recent Posts Widget With Thumbnails
recent-posts-widget-with-thumbnails
List the most recent posts with post titles, thumbnails, excerpts, authors, categories, dates and more!
jQuery Pin It Button for Images
jquery-pin-it-button-for-images
Highlights images on hover and adds a Pinterest "Pin It" button over them for easy pinning.
Hover Pin-It Developer Profile
1 plugin · 40 total installs
How We Detect Hover Pin-It
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/hover-pin-it/hover-pin-it.js/wp-content/plugins/hover-pin-it/hover-pin-it.jsHTML / DOM Fingerprints
pin-itjQuery().pinit[nopinit][dopinit]