
Flipbox – Awesome Flip Boxes & Image Overlay for WordPress Security & Risk Analysis
wordpress.org/plugins/image-hover-effects-ultimate-visual-composerCreate stunning CSS3 flip boxes in WordPress. 29 styles, 50+ animations, no coding. Works with any page builder (Elementor, WPBakery, Gutenberg, etc).
Is Flipbox – Awesome Flip Boxes & Image Overlay for WordPress Safe to Use in 2026?
Generally Safe
Score 99/100Flipbox – Awesome Flip Boxes & Image Overlay for WordPress has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The plugin "image-hover-effects-ultimate-visual-composer" v2.10.6 exhibits a mixed security posture. While it demonstrates good practices in several areas, such as a high percentage of prepared SQL statements and properly escaped outputs, there are notable concerns. The static analysis reveals a single unprotected AJAX handler, which represents a significant entry point without proper authentication or authorization checks. This is a critical weakness that could be exploited by an attacker. Furthermore, the taint analysis identified two high-severity flows with unsanitized paths, indicating potential for malicious input to lead to unintended consequences, possibly including arbitrary file access or manipulation.
The vulnerability history, though currently showing no unpatched CVEs, indicates a past high-severity vulnerability related to Authorization Bypass Through User-Controlled Key. This suggests a recurring pattern of authorization weaknesses. The presence of a single unprotected AJAX handler, coupled with past authorization bypass issues and high-severity taint flows, points to potential vulnerabilities in how user input is handled and authorized. While the plugin has strengths in its output escaping and SQL usage, these specific identified weaknesses warrant attention and mitigation.
Key Concerns
- Unprotected AJAX handler
- High severity unsanitized path taint flow (x2)
- Past high severity vulnerability (Authorization Bypass)
Flipbox – Awesome Flip Boxes & Image Overlay for WordPress Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Flipbox – Awesomes Flip Boxes Image Overlay <= 2.6.0 - Authenticated (Admin+) Arbitrary Options Update
Flipbox – Awesome Flip Boxes & Image Overlay for WordPress Release Timeline
Flipbox – Awesome Flip Boxes & Image Overlay for WordPress Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Flipbox – Awesome Flip Boxes & Image Overlay for WordPress Attack Surface
AJAX Handlers 3
Shortcodes 2
WordPress Hooks 24
Maintenance & Trust
Flipbox – Awesome Flip Boxes & Image Overlay for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
Flipbox – Awesome Flip Boxes & Image Overlay for WordPress Alternatives
Flip Cards Module For Divi
flip-cards-module-divi
A simple plugin that adds a flip cards module in the Divi builder.
Flip Block – Create Flipbox Overlays and Hovers
flip-block
A simple block to create a flip card in WordPress.
Fancy Elementor Flipbox
fancy-elementor-flipbox
Create flip box and 6 more effects with front and back side options
Image Hover Effects – WordPress Plugin
image-hover-effects
Create stunning image hover effects with animated captions and overlays. Fully responsive, lightweight, and easy to use.
Flipbox
flipbox
Deliver your content beautifully to grab attention with an animated Flipbox block.
Flipbox – Awesome Flip Boxes & Image Overlay for WordPress Developer Profile
6 plugins · 31K total installs
How We Detect Flipbox – Awesome Flip Boxes & Image Overlay for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/image-hover-effects-ultimate-visual-composer/asset/backend/js/admin-recommended.js/wp-content/plugins/image-hover-effects-ultimate-visual-composer/asset/backend/css/admin-style.css/wp-content/plugins/image-hover-effects-ultimate-visual-composer/asset/public/css/frontend.css/wp-content/plugins/image-hover-effects-ultimate-visual-composer/asset/public/js/frontend.js/wp-content/plugins/image-hover-effects-ultimate-visual-composer/asset/backend/js/admin-recommended.js/wp-content/plugins/image-hover-effects-ultimate-visual-composer/asset/backend/js/admin-style.js/wp-content/plugins/image-hover-effects-ultimate-visual-composer/asset/public/js/frontend.jsimage-hover-effects-ultimate-visual-composer/asset/backend/js/admin-recommended.js?ver=image-hover-effects-ultimate-visual-composer/asset/backend/css/admin-style.css?ver=image-hover-effects-ultimate-visual-composer/asset/public/css/frontend.css?ver=image-hover-effects-ultimate-visual-composer/asset/public/js/frontend.js?ver=HTML / DOM Fingerprints
oxi-flip-box-wrapperoxi-flip-boxes-main-wrapperoxi-flip-box-bodyoxi-flip-boxes-main-contentoxi-flip-box-frontend-datadata-oxi-flip-box-idoxi_flip_admin_recommended[oxilab_flip_box id=