Hydrogen Directory Security & Risk Analysis

wordpress.org/plugins/hydrogen-directory

The simplest, lightest way to manage and display a directory of anything.

0 active installs v1.3.0 PHP + WP 3.0+ Updated Unknown
churchclubdirectoryemployeepeople
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Hydrogen Directory Safe to Use in 2026?

Generally Safe

Score 100/100

Hydrogen Directory has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "hydrogen-directory" plugin v1.3.0 exhibits a strong security posture based on the provided static analysis. The plugin demonstrates excellent adherence to security best practices, with all identified entry points (AJAX handlers, REST API routes, and shortcodes) appearing to have appropriate authentication and permission checks. The absence of dangerous functions, file operations, and external HTTP requests further contributes to its security. Furthermore, the code's diligent use of prepared statements for SQL queries and robust output escaping (99%) significantly mitigates common web vulnerabilities like SQL injection and Cross-Site Scripting.

While the static analysis reveals no critical or high-severity issues in taint flows, and the vulnerability history is clean, a slightly larger attack surface (4 entry points) than might be ideal is present. The single shortcode is an entry point, and while not explicitly stated as unprotected, it's a potential area for future scrutiny if any user-controlled data is processed without strict sanitization. The plugin's clean vulnerability history is a positive indicator of good development practices, but it's important to note that a lack of past vulnerabilities does not guarantee future invulnerability. Overall, this plugin appears to be developed with security in mind, presenting a low-risk profile.

Vulnerabilities
None known

Hydrogen Directory Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Hydrogen Directory Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
107 escaped
Nonce Checks
1
Capability Checks
4
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

99% escaped108 total outputs
Attack Surface

Hydrogen Directory Attack Surface

Entry Points4
Unprotected0

REST API Routes 3

GET/wp-json/hydrogen-directory/v1/previewinit\block.php:30
GET/wp-json/hydrogen-directory/v1/taxonomiesinit\block.php:76
GET/wp-json/hydrogen-directory/v1/terms/(?P<taxonomy>[a-zA-Z0-9_-]+)init\block.php:85

Shortcodes 1

[hydrogen_directory] init\init.php:177
WordPress Hooks 25
actionload-post.phpinit\admin\position-meta-box.php:137
actionload-post-new.phpinit\admin\position-meta-box.php:138
actionadd_meta_boxes_hy_directoryinit\admin\position-meta-box.php:141
actionsave_postinit\admin\position-meta-box.php:142
actioninitinit\block.php:22
actionrest_api_initinit\block.php:100
actionenqueue_block_editor_assetsinit\block.php:307
actioninitinit\init.php:283
actionadmin_initinit\init.php:309
actionadmin_menuinit\init.php:318
filterhydir_shortcode_meatinit\shortcode.php:234
filtertaxonomy_templateinit\templates.php:29
filterarchive_templateinit\templates.php:57
filtersingle_templateinit\templates.php:85
filterhydir_content_modeutil\column-fill.php:42
filterhydir_excerpt_lengthutil\column-fill.php:45
filterhydir_list_show_contentutil\column-fill.php:50
filterhydir_list_full_contentutil\column-fill.php:53
filterhydir_list_excerpt_lengthutil\column-fill.php:56
filterhydir_card_show_contentutil\column-fill.php:61
filterhydir_card_full_contentutil\column-fill.php:64
filterhydir_card_excerpt_lengthutil\column-fill.php:67
filterhydir_text_show_contentutil\column-fill.php:72
filterhydir_text_full_contentutil\column-fill.php:75
filterhydir_text_excerpt_lengthutil\column-fill.php:78
Maintenance & Trust

Hydrogen Directory Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedUnknown
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Hydrogen Directory Developer Profile

LBell

5 plugins · 6K total installs

85
trust score
Avg Security Score
96/100
Avg Patch Time
51 days
View full developer profile
Detection Fingerprints

How We Detect Hydrogen Directory

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/hydrogen-directory/css/list-card.css/wp-content/plugins/hydrogen-directory/css/hydir.css/wp-content/plugins/hydrogen-directory/build/block.json
Script Paths
/wp-content/plugins/hydrogen-directory/build/index.js
Version Parameters
hydrogen-directory/css/list-card.css?ver=hydrogen-directory/css/hydir.css?ver=

HTML / DOM Fingerprints

CSS Classes
hydir-blockhydir-block-listhydir-block-cardhydir-entryhydir-entry__titlehydir-entry__contenthydir-entry__metahydir-entry__meta-item
Data Attributes
data-hydir-style
REST Endpoints
/wp-json/hydrogen-directory/v1/preview/wp-json/hydrogen-directory/v1/taxonomies/wp-json/hydrogen-directory/v1/terms/
Shortcode Output
[hydrogen_directory
FAQ

Frequently Asked Questions about Hydrogen Directory