
Image Hover Effects – WordPress Plugin Security & Risk Analysis
wordpress.org/plugins/image-hover-effectsCreate stunning image hover effects with animated captions and overlays. Fully responsive, lightweight, and easy to use.
Is Image Hover Effects – WordPress Plugin Safe to Use in 2026?
Generally Safe
Score 99/100Image Hover Effects – WordPress Plugin has a strong security track record. Known vulnerabilities have been patched promptly.
The 'image-hover-effects' plugin version 5.6 demonstrates a generally strong security posture based on the static analysis. The code shows excellent adherence to secure coding practices, with 100% of SQL queries using prepared statements and 98% of output being properly escaped. The presence of nonce and capability checks on entry points, combined with zero unsanitized paths in taint analysis, further strengthens its defenses. The attack surface appears minimal, with all identified entry points having authorization checks in place.
However, the plugin's vulnerability history presents a significant concern. Two medium-severity vulnerabilities have been documented in the past, specifically Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS). While there are currently no unpatched CVEs, the recurrence of these common vulnerability types in the past suggests a potential for future weaknesses if not diligently addressed. The last reported vulnerability was in November 2023, indicating that while recent, it's not entirely in the distant past.
In conclusion, the current codebase appears robust and well-secured against common static vulnerabilities. The plugin developers have implemented many good security practices. The primary weakness lies in the historical pattern of security flaws, particularly XSS and CSRF, which warrants continued vigilance and thorough review of any future updates to ensure these types of vulnerabilities do not reappear.
Key Concerns
- Past medium severity vulnerabilities (XSS/CSRF)
Image Hover Effects – WordPress Plugin Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Image Hover Effects <= 5.5 - Cross-Site Request Forgery
Image Hover Effects <= 5.4 - Authenticated (Administrator+) Stored Cross-Site Scripting
Image Hover Effects – WordPress Plugin Code Analysis
Output Escaping
Data Flow Analysis
Image Hover Effects – WordPress Plugin Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
Image Hover Effects – WordPress Plugin Maintenance & Trust
Maintenance Signals
Community Trust
Image Hover Effects – WordPress Plugin Alternatives
Image Hover Effects – Elementor Addon
image-hover-effects-addon-for-elementor
Add creative image hover effects to Elementor page builder. Easily customize title and content and effects with intuitive interface.
Hover Effects – easily create any hover effect
hover-effects
Hover Effect is easily applied to your own elements, modified or just used for inspiration.
Advanced Image Hover Effect for Elementor
advanced-image-hover-effect-for-elementor
Best Addons for Image Hover effect for Elementor. Create Awesome Image Hover Effects with built in 25+ effect.
Hover Effects With Lightbox For WPBakery Page Builder (formely Visual Composer)
hover-effects-with-lightbox-vc-extension
Add images to your pages with beautiful hover effects and captions.
Exclusive Hover effects
exclusive-hover-effects
Exclusive HOver effects have few hover effects on images,buttons for make your website stunning and beautiful
Image Hover Effects – WordPress Plugin Developer Profile
9 plugins · 8K total installs
How We Detect Image Hover Effects – WordPress Plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/image-hover-effects/admin/style.css/wp-content/plugins/image-hover-effects/admin/jquery-ui.min.css/wp-content/plugins/image-hover-effects/admin/admin.js/wp-content/plugins/image-hover-effects/admin/admin.jsimage-hover-effects/admin/style.css?ver=image-hover-effects/admin/jquery-ui.min.css?ver=image-hover-effects/admin/admin.js?ver=HTML / DOM Fingerprints
wrapperse-saved-conoverlay-messageaccordiancontentcatnameform-controlid="caption"id="faqs-container"class="accordian"class="accordian content"class="button topshortcode"class="dashicons dashicons-shortcode"+12 morelaAjax/wp-json/wp/v2/media[image-caption-hover]