Mirror Hours Lite Security & Risk Analysis

wordpress.org/plugins/mirror-hours-lite

Create mirror hour readings in WordPress with editable texts, multilingual starter content, search, and visual style controls.

0 active installs v1.2.14 PHP 7.4+ WP 6.0+ Updated Apr 6, 2026
angel-numbersmirror-hoursnumerologyspiritual-signsspirituality
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Mirror Hours Lite Safe to Use in 2026?

Generally Safe

Score 100/100

Mirror Hours Lite has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "mirror-hours-lite" v1.2.14 plugin exhibits a generally strong security posture based on the provided static analysis. It demonstrates excellent adherence to secure coding practices, with all SQL queries utilizing prepared statements and a very high percentage of output being properly escaped. The plugin also incorporates both nonce and capability checks, indicating an effort to protect against common WordPress vulnerabilities. Furthermore, the absence of dangerous functions, file operations, and external HTTP requests is a positive sign.

However, the taint analysis reveals four flows with unsanitized paths. While these are not classified as critical or high severity, they represent potential entry points for unexpected data handling and warrant careful review. The presence of six shortcodes as entry points, although currently protected, also constitutes a notable attack surface that could become a concern if future updates introduce vulnerabilities within their logic. The vulnerability history being entirely clear is a significant strength, suggesting a history of stable and secure development.

In conclusion, the plugin is built on a solid foundation of secure coding practices. The primary area for attention lies in the identified unsanitized paths within the taint analysis, which should be investigated for potential impact and mitigation. The shortcode attack surface, while currently secured, is a factor to monitor. Overall, the plugin presents a low-risk profile, with the taint analysis being the most significant point for further scrutiny.

Key Concerns

  • Taint flows with unsanitized paths
Vulnerabilities
None known

Mirror Hours Lite Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Mirror Hours Lite Release Timeline

v1.2.14Current
Code Analysis
Analyzed Apr 16, 2026

Mirror Hours Lite Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
497 escaped
Nonce Checks
2
Capability Checks
5
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

99% escaped500 total outputs
Data Flows · Security
4 unsanitized

Data Flow Analysis

4 flows4 with unsanitized paths
render_search_shortcode (includes/class-ccsn-renderer.php:166)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Mirror Hours Lite Attack Surface

Entry Points6
Unprotected0

Shortcodes 6

[ccsn_sign_hub] includes/class-ccsn-renderer.php:24
[ccsn_sign_search] includes/class-ccsn-renderer.php:25
[ccsn_equal_hours] includes/class-ccsn-renderer.php:26
[ccsn_hub_sinais] includes/class-ccsn-renderer.php:29
[ccsn_pesquisa_sinais] includes/class-ccsn-renderer.php:30
[ccsn_horas_iguais] includes/class-ccsn-renderer.php:31
WordPress Hooks 11
actionadmin_menuincludes/class-ccsn-admin.php:21
actionadmin_initincludes/class-ccsn-admin.php:22
actionadmin_initincludes/class-ccsn-admin.php:23
actionadmin_enqueue_scriptsincludes/class-ccsn-admin.php:24
actioninitincludes/class-ccsn-renderer.php:21
filterquery_varsincludes/class-ccsn-renderer.php:22
actionwp_enqueue_scriptsincludes/class-ccsn-renderer.php:33
actiontemplate_redirectincludes/class-ccsn-renderer.php:34
actionwp_headincludes/class-ccsn-renderer.php:35
actioninitmirror-hours-lite.php:844
actionplugins_loadedmirror-hours-lite.php:1000
Maintenance & Trust

Mirror Hours Lite Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedApr 6, 2026
PHP min version7.4
Downloads50

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Mirror Hours Lite Developer Profile

oportowebdesign

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Mirror Hours Lite

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mirror-hours-lite/assets/css/frontend.css/wp-content/plugins/mirror-hours-lite/assets/js/frontend.js
Script Paths
/wp-content/plugins/mirror-hours-lite/assets/js/frontend.js
Version Parameters
mirror-hours-lite/assets/css/frontend.css?ver=mirror-hours-lite/assets/js/frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
ccsn-wrapperccsn-hours-containerccsn-hour-item
HTML Comments
<!-- Generated by Mirror Hours Lite -->
Data Attributes
data-hour-iddata-hour-minute
JS Globals
ccsn_data
Shortcode Output
[mirror_hours_lite]
FAQ

Frequently Asked Questions about Mirror Hours Lite