Rotating Hero Image Security & Risk Analysis

wordpress.org/plugins/rotating-hero-image

Hero images on websites are great, but having the same one appear all the time gets... really boring. And using a slideshow on a page can add too much …

30 active installs v1.0.7 PHP + WP 5.4+ Updated Feb 10, 2023
hero-bannerhero-imagerotating-imagetimer
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Rotating Hero Image Safe to Use in 2026?

Generally Safe

Score 85/100

Rotating Hero Image has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "rotating-hero-image" plugin v1.0.7 exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of dangerous functions, reliance on prepared statements for SQL queries, and proper output escaping are excellent security practices. The plugin also demonstrates good security awareness with the presence of nonce and capability checks. Furthermore, the complete lack of known vulnerabilities, both past and present, indicates a history of diligent security focus from the developers. There are no identified taint flows, unsanitized paths, or file operations that would pose an immediate risk. The attack surface is minimal, with only one shortcode identified, and importantly, none of the entry points appear to be unprotected.

Vulnerabilities
None known

Rotating Hero Image Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Rotating Hero Image Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
0
59 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

100% escaped59 total outputs
Attack Surface

Rotating Hero Image Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[wsx_hero_image] rotating-hero-image.php:105
WordPress Hooks 8
actionadmin_enqueue_scriptsadmin\rotating-hero-image-admin.php:17
actioninitadmin\rotating-hero-image-admin.php:19
actionadd_meta_boxesadmin\rotating-hero-image-admin.php:21
actionsave_postadmin\rotating-hero-image-admin.php:23
actionadmin_menuadmin\rotating-hero-image-admin.php:25
actionadmin_initadmin\rotating-hero-image-admin.php:27
actionadmin_initadmin\rotating-hero-image-admin.php:29
actionwsxhi_categories_edit_form_fieldsadmin\rotating-hero-image-admin.php:31
Maintenance & Trust

Rotating Hero Image Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedFeb 10, 2023
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs30
Developer Profile

Rotating Hero Image Developer Profile

wsxplugindev

4 plugins · 720 total installs

71
trust score
Avg Security Score
89/100
Avg Patch Time
253 days
View full developer profile
Detection Fingerprints

How We Detect Rotating Hero Image

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/rotating-hero-image/admin/css/admin.css/wp-content/plugins/rotating-hero-image/admin/js/admin.js/wp-content/plugins/rotating-hero-image/public/js/rotating-hero-image.js
Script Paths
wp-content/plugins/rotating-hero-image/admin/js/admin.js
Version Parameters
rotating-hero-image/admin/css/admin.css?ver=rotating-hero-image/admin/js/admin.js?ver=rotating-hero-image/public/js/rotating-hero-image.js?ver=

HTML / DOM Fingerprints

CSS Classes
wsxhi-build-button-fieldset
Data Attributes
data-link-typedata-button-textdata-button-link
JS Globals
wsxhi_admin_options
Shortcode Output
<div class="wsxhi-hero-image-container<img src="<div class="wsxhi-hero-image-overlay<div class="wsxhi-hero-image-caption
FAQ

Frequently Asked Questions about Rotating Hero Image