Meet Hour Video Conference Security & Risk Analysis

wordpress.org/plugins/meet-hour-video-conference

Discover the power of video conferencing with Meet Hour. Learn what video conferencing is, explore its diverse applications across industries, and fin …

10 active installs v1.0 PHP 7.4+ WP 5.0+ Updated Apr 18, 2025
hourmeetmeet-hour-video-conferencemeethourmeetings
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Meet Hour Video Conference Safe to Use in 2026?

Generally Safe

Score 92/100

Meet Hour Video Conference has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "meet-hour-video-conference" plugin version 1.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices by using prepared statements for all SQL queries and properly escaping nearly all output. The absence of known CVEs and critical taint flows is also a strong indicator of a generally secure codebase in these areas. However, a significant concern arises from the large number of unprotected AJAX handlers. With 6 AJAX handlers identified and 5 lacking any form of authentication or authorization checks, this presents a substantial attack surface. This means that any user, even an unauthenticated one, could potentially trigger these functions, leading to unintended consequences or further exploitation if combined with other weaknesses.

The vulnerability history being entirely clear suggests that the developers have a good track record or the plugin hasn't been extensively targeted or audited in the past. While this is reassuring, it doesn't negate the immediate risks identified in the static analysis. The presence of a bundled library, Guzzle, while not inherently a vulnerability, could become a risk if it's an outdated version with known security flaws, though this information is not provided.

In conclusion, while the plugin shows strengths in data handling and output sanitization, the numerous unprotected AJAX entry points represent a critical weakness that needs immediate attention. This plugin's security is compromised by its open AJAX endpoints, outweighing its positive attributes in other areas. Without addressing these unprotected handlers, the plugin remains susceptible to attacks that could be initiated by unauthenticated users.

Key Concerns

  • 5 unprotected AJAX handlers
  • Bundled Guzzle library (potential outdated risk)
Vulnerabilities
None known

Meet Hour Video Conference Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Meet Hour Video Conference Release Timeline

v1.0Current
Code Analysis
Analyzed Apr 16, 2026

Meet Hour Video Conference Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
4 prepared
Unescaped Output
1
198 escaped
Nonce Checks
5
Capability Checks
0
File Operations
2
External Requests
0
Bundled Libraries
1

Bundled Libraries

Guzzle

SQL Query Safety

100% prepared4 total queries

Output Escaping

99% escaped199 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
meethour_token_page (includes/meethour-token.php:12)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
5 unprotected

Meet Hour Video Conference Attack Surface

Entry Points7
Unprotected5

AJAX Handlers 6

authwp_ajax_meethour_fetch_contactsincludes/meethour-guests.php:170
authwp_ajax_meethour_fetch_upcoming_meetingsincludes/meethour-meeting.php:243
noprivwp_ajax_meethour_fetch_upcoming_meetingsincludes/meethour-meeting.php:244
authwp_ajax_meethour_fetch_recordingsincludes/meethour-recording.php:242
authwp_ajax_mhvconf_set_permalink_optionincludes/meethour-scheduler.php:898
authwp_ajax_mhvconf_meethour_deactivatemeethour.php:188

Shortcodes 1

[meethour] meethour.php:103
WordPress Hooks 40
actionadmin_enqueue_scriptsincludes/frontend-scripts.php:286
actionadmin_headincludes/meethour-guests.php:95
actiondelete_user_formincludes/meethour-guests.php:175
actiondelete_userincludes/meethour-guests.php:215
actionuser_registerincludes/meethour-guests.php:243
actionprofile_updateincludes/meethour-guests.php:269
actionadmin_noticesincludes/meethour-guests.php:306
filtermanage_users_columnsincludes/meethour-guests.php:311
filtermanage_users_custom_columnincludes/meethour-guests.php:333
actioninitincludes/meethour-meeting.php:37
filtermanage_mhvconf_meetings_posts_columnsincludes/meethour-meeting.php:38
actionpre_get_postsincludes/meethour-meeting.php:138
actionwp_trash_postincludes/meethour-meeting.php:247
actionbefore_delete_postincludes/meethour-meeting.php:275
actionadmin_footerincludes/meethour-meeting.php:516
actionadmin_noticesincludes/meethour-meeting.php:533
actioninitincludes/meethour-meeting.php:560
filterregister_post_type_argsincludes/meethour-meeting.php:570
actionrestrict_manage_postsincludes/meethour-meeting.php:596
actionpre_get_postsincludes/meethour-meeting.php:607
actionpost_submitbox_misc_actionsincludes/meethour-meeting.php:640
actionquick_edit_custom_boxincludes/meethour-meeting.php:683
filtertemplate_includeincludes/meethour-meeting.php:697
actioninitincludes/meethour-meeting.php:700
actioninitincludes/meethour-recording.php:28
filtermanage_mhvconf_recordings_posts_columnsincludes/meethour-recording.php:30
actionmanage_mhvconf_recordings_posts_custom_columnincludes/meethour-recording.php:47
actionadmin_headincludes/meethour-recording.php:263
actionadmin_noticesincludes/meethour-recording.php:278
actionadd_meta_boxesincludes/meethour-scheduler.php:29
actionmanage_mhvconf_meetings_posts_custom_columnincludes/meethour-scheduler.php:42
filterenter_title_hereincludes/meethour-scheduler.php:52
actionsave_post_mhvconf_meetingsincludes/meethour-scheduler.php:255
actionsave_post_mhvconf_meetingsincludes/meethour-scheduler.php:678
actionadmin_headincludes/meethour-scheduler.php:858
actionadmin_noticesincludes/meethour-scheduler.php:884
filterredirect_post_locationincludes/meethour-scheduler.php:887
actionadmin_noticesincludes/meethour-token.php:174
actionadmin_menumeethour.php:77
filterpost_row_actionsmeethour.php:90
Maintenance & Trust

Meet Hour Video Conference Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedApr 18, 2025
PHP min version7.4
Downloads641

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Meet Hour Video Conference Developer Profile

meethour

1 plugin · 10 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Meet Hour Video Conference

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/meet-hour-video-conference/assets/css/frontend.css/wp-content/plugins/meet-hour-video-conference/assets/js/frontend.js
Script Paths
/wp-content/plugins/meet-hour-video-conference/assets/js/frontend.js
Version Parameters
meet-hour-video-conference/assets/css/frontend.css?ver=meet-hour-video-conference/assets/js/frontend.js?ver=

HTML / DOM Fingerprints

Data Attributes
id="mhConferenceFrame0"name="mhConferenceFrame0"
Shortcode Output
<iframe allow="camera; microphone; display-capture; autoplay; clipboard-write" src="https://meethour.io/name="mhConferenceFrame0"id="mhConferenceFrame0"allowfullscreen="true"
FAQ

Frequently Asked Questions about Meet Hour Video Conference