
Hoverswap Security & Risk Analysis
wordpress.org/plugins/hoverswapSwaps the content of a tag with the content of its title when the user hovers over it.
Is Hoverswap Safe to Use in 2026?
Generally Safe
Score 85/100Hoverswap has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'hoverswap' v1.0 exhibits a seemingly strong security posture based on the provided static analysis. The absence of identified AJAX handlers, REST API routes, shortcodes, and cron events suggests a very limited attack surface, which is a positive indicator. Furthermore, the code signals show no dangerous functions, no raw SQL queries (all are prepared), no file operations, no external HTTP requests, and no bundled libraries. This indicates good development practices in these areas.
However, a significant concern arises from the output escaping analysis. With 2 total outputs and 0% properly escaped, this indicates a potential for Cross-Site Scripting (XSS) vulnerabilities. Any data displayed to users that is not properly escaped can be leveraged by attackers to inject malicious scripts. The absence of capability checks and nonce checks, combined with zero taint flows, might be a consequence of the limited attack surface, but it also means that even if an entry point were discovered, there would be no built-in authorization or CSRF protection.
The vulnerability history is also clean, with zero recorded CVEs. This is a positive sign, suggesting the plugin has not historically had exploitable flaws. However, it's crucial to remember that a clean history doesn't guarantee future security, especially when other potential weaknesses like unescaped output exist. In conclusion, while 'hoverswap' v1.0 benefits from a small attack surface and good practices in data handling (SQL) and external interactions, the complete lack of output escaping presents a notable risk that should be addressed.
Key Concerns
- Output escaping is not properly implemented
Hoverswap Security Vulnerabilities
Hoverswap Release Timeline
Hoverswap Code Analysis
Output Escaping
Hoverswap Attack Surface
WordPress Hooks 2
Maintenance & Trust
Hoverswap Maintenance & Trust
Maintenance Signals
Community Trust
Hoverswap Alternatives
Auto Image Attributes From Filename With Bulk Updater (Add Alt Text, Image Title For Image SEO)
auto-image-attributes-from-filename-with-bulk-updater
Automatically add Image Alt Text, Title, Caption and Description from Filename. Bulk update existing images. Great for Image SEO and Accessibility.
Enhanced Text Widget
enhanced-text-widget
An enhanced version of the text widget that supports Text, HTML, CSS, JavaScript, Flash, Shortcodes and PHP with linkable widget title.
Change Price Title for WooCommerce
change-wc-price-title
Easily rename, replace, or hide the WooCommerce price title (e.g., "Price:" → "Monthly Fee") — globally or per product. No coding required.
ImageComply – Alt Text Generator
imagecomply
ImageComply can generate alt text for your entire media gallery of images in the click of a button. Time saved, money saved.
Blur Text
blur-text
Blur Text with a shortcode. Unblur with a click or hover. Specify a blur color.
Hoverswap Developer Profile
4 plugins · 40 total installs
How We Detect Hoverswap
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
overhoverswap