Ultimate Hover Effects Security & Risk Analysis

wordpress.org/plugins/ultimate-hover-effects

Ultimate Hover Effects WordPress Plugin is an impressive powerfull modern, yet stylish hover effects for image captions.

300 active installs v2.9.4 PHP + WP 3.0.1+ Updated Jul 26, 2021
3dawesome-css3-effectsawesome-image-effectsresponsiveresponsive-image-effects
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Ultimate Hover Effects Safe to Use in 2026?

Generally Safe

Score 85/100

Ultimate Hover Effects has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The ultimate-hover-effects plugin, version 2.9.4, exhibits a generally strong security posture based on the provided static analysis. The absence of known CVEs and a clean vulnerability history are highly positive indicators. The code analysis reveals no dangerous functions, raw SQL queries, file operations, or external HTTP requests, all of which are excellent security practices. Furthermore, the plugin implements nonce and capability checks on its entry points, and all SQL queries are prepared statements. This demonstrates a diligent effort to adhere to WordPress security best practices.

However, there is a minor concern regarding output escaping. With 159 total outputs and 70% properly escaped, it means approximately 48 output instances may not be adequately sanitized. While taint analysis showed no unsanitized flows, this percentage of unescaped output represents a potential area for cross-site scripting (XSS) vulnerabilities, especially if user-supplied data is involved in these unescaped outputs. The attack surface is minimal with only 2 AJAX handlers and 1 shortcode, and importantly, none of these entry points are reported as unprotected, which is excellent.

Key Concerns

  • Significant percentage of unescaped output
Vulnerabilities
None known

Ultimate Hover Effects Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Ultimate Hover Effects Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
48
111 escaped
Nonce Checks
3
Capability Checks
6
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

70% escaped159 total outputs
Attack Surface

Ultimate Hover Effects Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 2

authwp_ajax_cmb2_oembed_handleradmin\cmb2\includes\CMB2_Ajax.php:51
noprivwp_ajax_cmb2_oembed_handleradmin\cmb2\includes\CMB2_Ajax.php:52

Shortcodes 1

[u_hover_effect] shortcodes\index.php:121
WordPress Hooks 42
actioncmb2_admin_initadmin\cmb2\example-functions.php:105
actioncmb2_initadmin\cmb2\example-functions.php:468
filterwp_prepare_attachment_for_jsadmin\cmb2\includes\CMB2.php:1469
actionadmin_enqueue_scriptsadmin\cmb2\includes\CMB2.php:1486
actioncmb2_save_options-page_fieldsadmin\cmb2\includes\CMB2_Ajax.php:54
filterget_post_metadataadmin\cmb2\includes\CMB2_Ajax.php:147
filterupdate_post_metadataadmin\cmb2\includes\CMB2_Ajax.php:150
filtercmb2_show_onadmin\cmb2\includes\CMB2_hookup.php:79
actionedit_form_topadmin\cmb2\includes\CMB2_hookup.php:115
actionedit_form_before_permalinkadmin\cmb2\includes\CMB2_hookup.php:119
actionedit_form_after_titleadmin\cmb2\includes\CMB2_hookup.php:123
actionedit_form_after_editoradmin\cmb2\includes\CMB2_hookup.php:127
actionadd_meta_boxesadmin\cmb2\includes\CMB2_hookup.php:131
actionadd_meta_boxesadmin\cmb2\includes\CMB2_hookup.php:134
actionadd_attachmentadmin\cmb2\includes\CMB2_hookup.php:135
actionedit_attachmentadmin\cmb2\includes\CMB2_hookup.php:136
actionsave_postadmin\cmb2\includes\CMB2_hookup.php:137
actionadd_meta_boxes_commentadmin\cmb2\includes\CMB2_hookup.php:150
actionedit_commentadmin\cmb2\includes\CMB2_hookup.php:151
filtermanage_edit-comments_columnsadmin\cmb2\includes\CMB2_hookup.php:154
actionmanage_comments_custom_columnadmin\cmb2\includes\CMB2_hookup.php:155
actionshow_user_profileadmin\cmb2\includes\CMB2_hookup.php:164
actionedit_user_profileadmin\cmb2\includes\CMB2_hookup.php:165
actionuser_new_formadmin\cmb2\includes\CMB2_hookup.php:166
actionpersonal_options_updateadmin\cmb2\includes\CMB2_hookup.php:168
actionedit_user_profile_updateadmin\cmb2\includes\CMB2_hookup.php:169
actionuser_registeradmin\cmb2\includes\CMB2_hookup.php:170
filtermanage_users_columnsadmin\cmb2\includes\CMB2_hookup.php:173
filtermanage_users_custom_columnadmin\cmb2\includes\CMB2_hookup.php:174
actioncreated_termadmin\cmb2\includes\CMB2_hookup.php:222
actionedited_termsadmin\cmb2\includes\CMB2_hookup.php:223
actiondelete_termadmin\cmb2\includes\CMB2_hookup.php:224
actioncmb2_do_oembedadmin\cmb2\includes\helper-functions.php:131
filteris_protected_metaadmin\cmb2\includes\rest-api\CMB2_REST.php:144
actioninitadmin\cmb2\init.php:126
actionwp_enqueue_scriptsultimate-hover-effects.php:42
actioninitultimate-hover-effects.php:48
filterwidget_textultimate-hover-effects.php:74
filterwidget_textultimate-hover-effects.php:75
filtermanage_u_hover_effect_posts_columnsultimate-hover-effects.php:78
actionmanage_u_hover_effect_posts_custom_columnultimate-hover-effects.php:79
filterpost_updated_messagesultimate-hover-effects.php:99
Maintenance & Trust

Ultimate Hover Effects Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedJul 26, 2021
PHP min version
Downloads69K

Community Trust

Rating76/100
Number of ratings20
Active installs300
Developer Profile

Ultimate Hover Effects Developer Profile

wpeffects

1 plugin · 300 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Ultimate Hover Effects

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ultimate-hover-effects/assets/css/grid.css/wp-content/plugins/ultimate-hover-effects/assets/css/ultimate-hover.css/wp-content/plugins/ultimate-hover-effects/assets/css/ihover.css/wp-content/plugins/ultimate-hover-effects/assets/css/caption.css/wp-content/plugins/ultimate-hover-effects/assets/css/custom.css/wp-content/plugins/ultimate-hover-effects/assets/css/responsive.css/wp-content/plugins/ultimate-hover-effects/assets/js/ultimate-hover.min.js
Version Parameters
ultimate-hover-effects/assets/css/grid.css?ver=ultimate-hover-effects/assets/css/ultimate-hover.css?ver=ultimate-hover-effects/assets/css/ihover.css?ver=ultimate-hover-effects/assets/css/caption.css?ver=ultimate-hover-effects/assets/css/custom.css?ver=ultimate-hover-effects/assets/css/responsive.css?ver=ultimate-hover-effects/assets/js/ultimate-hover.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
ultimate-hover-effectuhf-griduhf-itemuhf-overlayuhf-captionuhf-contentuhf-titleuhf-description+100 more
Data Attributes
data-effect
JS Globals
uhe_custom_meta
Shortcode Output
[ultimate_hover_effects][ultimate_hover_effects_single]
FAQ

Frequently Asked Questions about Ultimate Hover Effects