
LH Web Application Security & Risk Analysis
wordpress.org/plugins/lh-web-applicationMakes your WordPress website into a fully configurable web app.
Is LH Web Application Safe to Use in 2026?
Generally Safe
Score 85/100LH Web Application has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The lh-web-application plugin v1.28 exhibits a generally good security posture based on the provided static analysis and vulnerability history. The absence of any known CVEs and a clean vulnerability history are positive indicators. The code analysis reveals a small attack surface with no unprotected entry points, which is commendable. The presence of nonce and capability checks, along with a limited number of file operations and no external HTTP requests, further contribute to a secure foundation.
However, there are notable areas of concern that warrant attention. The most significant risk stems from the SQL queries; 100% of them are not using prepared statements. This could lead to SQL injection vulnerabilities if user-supplied data is not rigorously sanitized before being used in queries. Additionally, the low percentage of properly escaped output (11%) suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities across numerous output points. While the taint analysis did not reveal critical or high severity flows, the presence of one unsanitized path is a potential precursor to issues, especially when combined with the unescaped output.
In conclusion, the plugin benefits from a minimal attack surface and a clean vulnerability track record. Nevertheless, the critical findings regarding raw SQL queries and widespread unescaped output present substantial security risks that could be exploited. Addressing these specific code-level weaknesses is paramount to improving the plugin's overall security.
Key Concerns
- SQL queries not using prepared statements
- Low percentage of properly escaped output
- Flows with unsanitized paths
LH Web Application Security Vulnerabilities
LH Web Application Release Timeline
LH Web Application Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
LH Web Application Attack Surface
Shortcodes 1
WordPress Hooks 28
Scheduled Events 2
Maintenance & Trust
LH Web Application Maintenance & Trust
Maintenance Signals
Community Trust
LH Web Application Alternatives
Super Progressive Web Apps
super-progressive-web-apps
SuperPWA helps you convert your WordPress website into a Progressive Web App instantly.
PWA
pwa
WordPress feature plugin to bring Progressive Web App (PWA) capabilities to Core
WP-AppKit – Mobile apps and PWA for WordPress
wp-appkit
Important ✋: beginning with version 1.5.3, we don't support anymore native iOS app. This is a tough choice we explain here.
SiteEase Progressive Web App
iflair-pwa-app
SiteEase Progressive Web App converts your WordPress website into a Progressive Web App (PWA) with offline support, caching strategies, and installabl …
miTT PWA FREE WP
mitt-pwa
miTT PWA FREE WP transforms your WordPress Website into a Progressive Web App (PWA) and makes it offline ready using Service Workers.
LH Web Application Developer Profile
89 plugins · 15K total installs
How We Detect LH Web Application
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/lh-web-application/inc/pwafunctional.css/wp-content/plugins/lh-web-application/inc/pwafunctional.js/wp-content/plugins/lh-web-application/inc/lh_web_application.css/wp-content/plugins/lh-web-application/inc/pwafunctional.jslh-web-application/inc/pwafunctional.css?ver=lh-web-application/inc/pwafunctional.js?ver=lh-web-application/inc/lh_web_application.css?ver=