
LH Relationships Security & Risk Analysis
wordpress.org/plugins/lh-relationshipsThis plugin allows allows the creation and publishing of triple relationships in RDF format.
Is LH Relationships Safe to Use in 2026?
Generally Safe
Score 85/100LH Relationships has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "lh-relationships" plugin v0.21 exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for all SQL queries, which significantly mitigates the risk of SQL injection vulnerabilities. It also incorporates nonce and capability checks, indicating an awareness of authorization and security controls. Furthermore, the plugin has no recorded vulnerability history (CVEs), suggesting a relatively stable and secure track record thus far.
However, the static analysis reveals significant concerns, particularly in output escaping and taint analysis. A critical finding is that 0% of the 65 total outputs are properly escaped. This makes the plugin highly susceptible to Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data could be directly rendered in the browser without sanitization. Additionally, the taint analysis indicates 9 out of 10 flows have unsanitized paths, with all of them being flagged as high severity. This strongly suggests that data originating from external sources is not being adequately validated or sanitized before being used in potentially sensitive operations, despite the absence of direct SQL injection risks.
In conclusion, while the plugin avoids common pitfalls like raw SQL and an exposed attack surface, the complete lack of output escaping and the prevalence of high-severity unsanitized taint flows present a substantial risk, primarily of XSS and potentially other injection-related vulnerabilities depending on how the unsanitized data is handled internally. The absence of a vulnerability history is positive but does not negate the immediate risks identified in the current code.
Key Concerns
- No output escaping
- High severity unsanitized taint flows
LH Relationships Security Vulnerabilities
LH Relationships Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
LH Relationships Attack Surface
WordPress Hooks 23
Scheduled Events 1
Maintenance & Trust
LH Relationships Maintenance & Trust
Maintenance Signals
Community Trust
LH Relationships Alternatives
Disable Feeds
disable-feeds
Disables all RSS/Atom/RDF feeds on your WordPress site.
Disable RSS, RDF, and Atom Feeds
disable-rss-rdf-atom-feeds
Disable all RSS, RDF, and Atom feeds on your WordPress site with the option to control behavior such as redirection or issuing a 404 error.
Feeds in Theme plugin
feeds-in-theme
Creates 4 feeds :
EmbedPress – PDF Embedder, Embed YouTube Videos, 3D FlipBook, Social feeds, Docs & more
embedpress
EmbedPress lets you embed videos, pages, social feeds, embed PDF 3D flipbooks & other content on WordPress without coding & enhance storytelling.
Buttonizer – Social Media Share Buttons, Social Icons, & Social Feeds
facebook-pagelike-widget
Floating Social Media Icons, Sticky Share Buttons, Facebook Feeds, & Popup builder. Also, create Call, Email, SMS, & Contact buttons to increa …
LH Relationships Developer Profile
77 plugins · 15K total installs
How We Detect LH Relationships
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.