Image Hover Effects For WPBakery Page Builder Security & Risk Analysis

wordpress.org/plugins/image-hover-effects-visual-composer-extension

Add stylish CSS3 hover effects with captions to images in WPBakery Page Builder. Create engaging animations that enhance your site’s visual appeal.

3K active installs v5.0 PHP + WP 3.5+ Updated Sep 17, 2025
animationscss3hover-effectsimageswpbakery
100
A · Safe
CVEs total1
Unpatched0
Last CVEJan 20, 2023
Safety Verdict

Is Image Hover Effects For WPBakery Page Builder Safe to Use in 2026?

Generally Safe

Score 100/100

Image Hover Effects For WPBakery Page Builder has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Jan 20, 2023Updated 6mo ago
Risk Assessment

The image-hover-effects-visual-composer-extension plugin exhibits a generally good security posture based on the static analysis. It demonstrates strong practices in handling SQL queries with prepared statements and a high percentage of properly escaped output. The absence of dangerous functions, file operations, and external HTTP requests further contributes to its security. The limited attack surface, with only one shortcode and no exposed AJAX or REST API endpoints without authentication, is also a positive indicator.

However, a notable concern arises from the vulnerability history, specifically the past medium-severity Cross-Site Scripting (XSS) vulnerability. While currently patched, the fact that an XSS vulnerability existed suggests that input sanitization might not be consistently robust. The lack of nonce checks and capability checks on the identified entry point (the shortcode) is also a weakness, as it leaves the shortcode potentially vulnerable to abuse if not properly validated or if it processes user-supplied data that is not thoroughly sanitized.

In conclusion, the plugin has strong technical foundations in secure coding practices like prepared statements and output escaping. Nevertheless, the historical XSS vulnerability and the absence of essential security checks on the shortcode highlight areas that require vigilant monitoring and potential improvement to prevent future security incidents. The plugin's strengths lie in its minimal attack surface and secure data handling, while its weaknesses are tied to its past vulnerability and the lack of comprehensive security checks on its existing entry points.

Key Concerns

  • Missing nonce checks on entry points
  • Missing capability checks on entry points
  • Historical medium severity XSS vulnerability
Vulnerabilities
1

Image Hover Effects For WPBakery Page Builder Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2023-23681medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Image Hover Effects For WPBakery Page Builder <= 4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode

Jan 20, 2023 Patched in 5.0 (368d)
Code Analysis
Analyzed Mar 16, 2026

Image Hover Effects For WPBakery Page Builder Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
23 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

96% escaped24 total outputs
Attack Surface

Image Hover Effects For WPBakery Page Builder Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[image-hover-effects-vc-free] plugin.class.php:15
WordPress Hooks 4
actionvc_before_initplugin.class.php:14
actioninitplugin.class.php:16
actionadmin_enqueue_scriptsplugin.class.php:17
actionadmin_noticesplugin.class.php:67
Maintenance & Trust

Image Hover Effects For WPBakery Page Builder Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 17, 2025
PHP min version
Downloads135K

Community Trust

Rating86/100
Number of ratings14
Active installs3K
Developer Profile

Image Hover Effects For WPBakery Page Builder Developer Profile

Labib Ahmed

9 plugins · 8K total installs

78
trust score
Avg Security Score
98/100
Avg Patch Time
239 days
View full developer profile
Detection Fingerprints

How We Detect Image Hover Effects For WPBakery Page Builder

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/image-hover-effects-visual-composer-extension/css/admin-styles.css/wp-content/plugins/image-hover-effects-visual-composer-extension/css/image-hover.css

HTML / DOM Fingerprints

CSS Classes
vc_image_hover_effects_freevc-image-hover-effects-vc-free
Shortcode Output
[image-hover-effects-vc-free]
FAQ

Frequently Asked Questions about Image Hover Effects For WPBakery Page Builder