
LH Web Application Security & Risk Analysis
wordpress.org/plugins/lh-web-applicationMakes your WordPress website into a fully configurable web app.
Is LH Web Application Safe to Use in 2026?
Generally Safe
Score 85/100LH Web Application has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The lh-web-application plugin v1.28 exhibits a generally good security posture based on the provided static analysis and vulnerability history. The absence of any known CVEs and a clean vulnerability history are positive indicators. The code analysis reveals a small attack surface with no unprotected entry points, which is commendable. The presence of nonce and capability checks, along with a limited number of file operations and no external HTTP requests, further contribute to a secure foundation.
However, there are notable areas of concern that warrant attention. The most significant risk stems from the SQL queries; 100% of them are not using prepared statements. This could lead to SQL injection vulnerabilities if user-supplied data is not rigorously sanitized before being used in queries. Additionally, the low percentage of properly escaped output (11%) suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities across numerous output points. While the taint analysis did not reveal critical or high severity flows, the presence of one unsanitized path is a potential precursor to issues, especially when combined with the unescaped output.
In conclusion, the plugin benefits from a minimal attack surface and a clean vulnerability track record. Nevertheless, the critical findings regarding raw SQL queries and widespread unescaped output present substantial security risks that could be exploited. Addressing these specific code-level weaknesses is paramount to improving the plugin's overall security.
Key Concerns
- SQL queries not using prepared statements
- Low percentage of properly escaped output
- Flows with unsanitized paths
LH Web Application Security Vulnerabilities
LH Web Application Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
LH Web Application Attack Surface
Shortcodes 1
WordPress Hooks 28
Scheduled Events 2
Maintenance & Trust
LH Web Application Maintenance & Trust
Maintenance Signals
Community Trust
LH Web Application Alternatives
Super Progressive Web Apps
super-progressive-web-apps
SuperPWA helps you convert your WordPress website into a Progressive Web App instantly.
PWA
pwa
WordPress feature plugin to bring Progressive Web App (PWA) capabilities to Core
WP-AppKit – Mobile apps and PWA for WordPress
wp-appkit
Important ✋: beginning with version 1.5.3, we don't support anymore native iOS app. This is a tough choice we explain here.
SiteEase Progressive Web App
iflair-pwa-app
SiteEase Progressive Web App converts your WordPress website into a Progressive Web App (PWA) with offline support, caching strategies, and installabl …
miTT PWA FREE WP
mitt-pwa
miTT PWA FREE WP transforms your WordPress Website into a Progressive Web App (PWA) and makes it offline ready using Service Workers.
LH Web Application Developer Profile
77 plugins · 15K total installs
How We Detect LH Web Application
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/lh-web-application/inc/pwafunctional.css/wp-content/plugins/lh-web-application/inc/pwafunctional.js/wp-content/plugins/lh-web-application/inc/lh_web_application.css/wp-content/plugins/lh-web-application/inc/pwafunctional.jslh-web-application/inc/pwafunctional.css?ver=lh-web-application/inc/pwafunctional.js?ver=lh-web-application/inc/lh_web_application.css?ver=