HT Service – Roofing Service WordPress Plugin Security & Risk Analysis

wordpress.org/plugins/ht-service

HT Service is a Roofing Service WordPress Plugin.

30 active installs v1.1.3 PHP + WP 5.0+ Updated Dec 4, 2025
roofing-serviceserviceservice-boxservice-listservice-plugin
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is HT Service – Roofing Service WordPress Plugin Safe to Use in 2026?

Generally Safe

Score 100/100

HT Service – Roofing Service WordPress Plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The "ht-service" v1.1.3 plugin exhibits a generally positive security posture based on the provided static analysis. The absence of dangerous functions, file operations, and external HTTP requests, coupled with 100% of SQL queries utilizing prepared statements, are strong indicators of secure coding practices. The plugin also demonstrates a good understanding of WordPress security by including capability checks. However, the analysis highlights a notable concern: a significant portion of output (31%) is not properly escaped, presenting a potential cross-site scripting (XSS) vulnerability risk if user-supplied data is outputted without sanitization.

The plugin has a very small attack surface with only one entry point, a shortcode, and no unprotected AJAX handlers or REST API routes. Taint analysis shows no identified flows, suggesting no immediately apparent exploitable vulnerabilities in that area. The vulnerability history is clean, with no recorded CVEs, indicating a history of secure development or a lack of past scrutiny. Despite the lack of explicit nonce checks for the identified shortcode, the absence of other critical vulnerabilities and the clean history suggest that the risk, while present, may be mitigated by other factors not visible in this static analysis or by the nature of the shortcode's functionality. The overall security is good, but the unescaped output remains a key area for improvement.

Key Concerns

  • Significant portion of output not properly escaped
  • No nonce checks on the identified shortcode
Vulnerabilities
None known

HT Service – Roofing Service WordPress Plugin Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

HT Service – Roofing Service WordPress Plugin Release Timeline

v1.1.3Current
v1.1.2
v1.1.1
v1.1.0
v1.0.16
v1.0.15
v1.0.14
v1.0.13
v1.0.12
v1.0.11
v1.0.10
v1.0.9
v1.0.8
v1.0.7
v1.0.6
v1.0.5
Code Analysis
Analyzed Mar 16, 2026

HT Service – Roofing Service WordPress Plugin Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
45
100 escaped
Nonce Checks
0
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

69% escaped145 total outputs
Attack Surface

HT Service – Roofing Service WordPress Plugin Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[hts_service] admin\htservice_shortcode.php:85
WordPress Hooks 21
actionadmin_menuadmin\admin-init.php:17
actionadmin_enqueue_scriptsadmin\admin-init.php:40
actionadmin_enqueue_scriptsadmin\class.settings-api.php:30
filtercmb2_initadmin\htservice_custom-metabox.php:5
actioninitadmin\htservice_custom-post-type.php:79
actionadmin_initadmin\plugin-options.php:17
actionadmin_menuadmin\plugin-options.php:18
actionadmin_menuadmin\Recommended_Plugins.php:78
actionadmin_enqueue_scriptsadmin\Recommended_Plugins.php:79
filtersingle_templatehtservice.php:26
filterarchive_templatehtservice.php:39
actionadmin_inithtservice.php:100
filterviews_edit-htservicehtservice.php:160
actionhtservice_category_pre_add_formhtservice.php:161
actionwsa_form_bottom_pro_themeshtservice.php:163
actionelementor/initincludes\helper-function.php:21
actionelementor/widgets/registerinit.php:12
actionelementor/widgets/widgets_registeredinit.php:14
actionwp_enqueue_scriptsinit.php:31
actioninitinit.php:45
actioninitinit.php:54
Maintenance & Trust

HT Service – Roofing Service WordPress Plugin Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 4, 2025
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs30
Developer Profile

HT Service – Roofing Service WordPress Plugin Developer Profile

DevItems

13 plugins · 170K total installs

76
trust score
Avg Security Score
95/100
Avg Patch Time
97 days
View full developer profile
Detection Fingerprints

How We Detect HT Service – Roofing Service WordPress Plugin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ht-service/admin/css/htservice-admin-style.css/wp-content/plugins/ht-service/admin/js/htservice-admin-script.js/wp-content/plugins/ht-service/assets/css/htservice-public.css/wp-content/plugins/ht-service/assets/js/htservice-public.js/wp-content/plugins/ht-service/includes/single-htservice.php/wp-content/plugins/ht-service/includes/archive-htservice.php
Script Paths
/wp-content/plugins/ht-service/admin/js/htservice-admin-script.js/wp-content/plugins/ht-service/assets/js/htservice-public.js
Version Parameters
htservice/style.css?ver=htservice/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
htservice-pagination
HTML Comments
<!-- Single template by post type --><!-- Archive template by post type --><!-- This notice for Cmb2 is not installed or activated or both. --><!-- Display tabs related to Serives in admin when user -->+9 more
Data Attributes
data-post-type="htservice"data-taxonomy="htservice_category"
JS Globals
htservice_pagination
Shortcode Output
<div class="htservice-pagination">
FAQ

Frequently Asked Questions about HT Service – Roofing Service WordPress Plugin