OnHover Link Preview Security & Risk Analysis

wordpress.org/plugins/onhover-link-preview

OnHover Link Preview plugin automatically adds link preview pop-ups so visitors can see the preview of the hyperlink without leaving your website, and …

10 active installs v1.0.2 PHP 5.6+ WP 5.9+ Updated Jan 16, 2024
blogembedslink-previewlinksmshots
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is OnHover Link Preview Safe to Use in 2026?

Generally Safe

Score 85/100

OnHover Link Preview has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

Based on the provided static analysis, the "onhover-link-preview" plugin version 1.0.2 exhibits a very strong security posture. The absence of any identified attack surface entry points, dangerous functions, or unsanitized taint flows is highly commendable and suggests robust development practices. Furthermore, the complete utilization of prepared statements for SQL queries and proper output escaping indicates a conscious effort to prevent common web vulnerabilities. The plugin also does not perform file operations or external HTTP requests, further reducing its attack surface.

While the static analysis reveals an excellent security foundation, the lack of nonce and capability checks on the identified entry points (even though there are zero) is a minor concern. If any entry points were to be introduced in future versions, the absence of these checks would immediately expose the plugin to potential security risks. The vulnerability history shows no recorded CVEs, which is a positive indicator. However, this also means there's no historical data to suggest how the developers handle security issues or patch vulnerabilities, which could be a latent concern if issues arise in the future.

In conclusion, the plugin is currently in an excellent security state due to its minimal attack surface and well-handled code. The main area for potential improvement, should the plugin evolve, would be to ensure all future entry points are properly secured with nonce and capability checks. The absence of past vulnerabilities is positive, but diligence will be required for ongoing security.

Key Concerns

  • No nonce checks found
  • No capability checks found
Vulnerabilities
None known

OnHover Link Preview Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

OnHover Link Preview Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
8 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Freemius1.0

Output Escaping

100% escaped8 total outputs
Attack Surface

OnHover Link Preview Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionwp_enqueue_scriptson-hover-link-prev.php:71
actionadmin_enqueue_scriptson-hover-link-prev.php:83
actionadmin_menuon-hover-link-prev.php:118
actionadmin_initon-hover-link-prev.php:186
Maintenance & Trust

OnHover Link Preview Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedJan 16, 2024
PHP min version5.6
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

OnHover Link Preview Developer Profile

Rajin Sharwar

7 plugins · 340 total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect OnHover Link Preview

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/onhover-link-preview/assets/link-preview.css/wp-content/plugins/onhover-link-preview/assets/link-preview.js
Script Paths
/wp-content/plugins/onhover-link-preview/assets/link-preview.js
Version Parameters
onhover-link-preview/assets/link-preview.js?ver=onhover-link-preview/assets/link-preview.css?ver=

HTML / DOM Fingerprints

CSS Classes
on-hover-link-prev-warningon-hover-link-prev-warning-text
Data Attributes
data-settings-id
JS Globals
link_preview_vars
FAQ

Frequently Asked Questions about OnHover Link Preview