
OnHover Link Preview Security & Risk Analysis
wordpress.org/plugins/onhover-link-previewOnHover Link Preview plugin automatically adds link preview pop-ups so visitors can see the preview of the hyperlink without leaving your website, and …
Is OnHover Link Preview Safe to Use in 2026?
Generally Safe
Score 85/100OnHover Link Preview has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the provided static analysis, the "onhover-link-preview" plugin version 1.0.2 exhibits a very strong security posture. The absence of any identified attack surface entry points, dangerous functions, or unsanitized taint flows is highly commendable and suggests robust development practices. Furthermore, the complete utilization of prepared statements for SQL queries and proper output escaping indicates a conscious effort to prevent common web vulnerabilities. The plugin also does not perform file operations or external HTTP requests, further reducing its attack surface.
While the static analysis reveals an excellent security foundation, the lack of nonce and capability checks on the identified entry points (even though there are zero) is a minor concern. If any entry points were to be introduced in future versions, the absence of these checks would immediately expose the plugin to potential security risks. The vulnerability history shows no recorded CVEs, which is a positive indicator. However, this also means there's no historical data to suggest how the developers handle security issues or patch vulnerabilities, which could be a latent concern if issues arise in the future.
In conclusion, the plugin is currently in an excellent security state due to its minimal attack surface and well-handled code. The main area for potential improvement, should the plugin evolve, would be to ensure all future entry points are properly secured with nonce and capability checks. The absence of past vulnerabilities is positive, but diligence will be required for ongoing security.
Key Concerns
- No nonce checks found
- No capability checks found
OnHover Link Preview Security Vulnerabilities
OnHover Link Preview Code Analysis
Bundled Libraries
Output Escaping
OnHover Link Preview Attack Surface
WordPress Hooks 4
Maintenance & Trust
OnHover Link Preview Maintenance & Trust
Maintenance Signals
Community Trust
OnHover Link Preview Alternatives
Link Manager
link-manager
Enables the Link Manager that existed in WordPress until version 3.5.
Eazy Enable Blogroll
eazy-enable-blogroll
Eazy Enable Blogroll brings back the one and only WordPress Blogroll Feature, with nearly one click!
Link View
link-view
Display a link-list or link-slider in a post or page by using a shortcode.
Blogroll Links
blogroll-links
Display your blogroll links anywhere in posts or pages using a simple shortcode.
Blogroll Widget with RSS Feeds
blogroll-rss-widget
Displays the recent posts of your blogroll links via RSS Feeds in a customizable sidebar widget
OnHover Link Preview Developer Profile
7 plugins · 340 total installs
How We Detect OnHover Link Preview
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/onhover-link-preview/assets/link-preview.css/wp-content/plugins/onhover-link-preview/assets/link-preview.js/wp-content/plugins/onhover-link-preview/assets/link-preview.jsonhover-link-preview/assets/link-preview.js?ver=onhover-link-preview/assets/link-preview.css?ver=HTML / DOM Fingerprints
on-hover-link-prev-warningon-hover-link-prev-warning-textdata-settings-idlink_preview_vars