Valentine’s Day Hearts Security & Risk Analysis

wordpress.org/plugins/valentines-day-floating-hearts

Simple plugin to give a touch of Valentine's Day spirit!

100 active installs v2.0 PHP + WP 3.0.1+ Updated May 25, 2018
festivefloatingheartsvalentines-day
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Valentine’s Day Hearts Safe to Use in 2026?

Generally Safe

Score 85/100

Valentine’s Day Hearts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The "valentines-day-floating-hearts" v2.0 plugin exhibits a strong security posture based on the provided static analysis. There are no identified entry points such as AJAX handlers, REST API routes, or shortcodes that are exposed without proper authentication or capability checks. The code signals are also very positive, with no dangerous functions, all SQL queries using prepared statements, and all output properly escaped. Furthermore, the plugin avoids file operations, external HTTP requests, and appears to implement at least one capability check.

The absence of any identified taint flows or known vulnerabilities in its history is a significant strength, indicating a history of secure development or a lack of targeted attacks. The plugin's minimal attack surface and robust internal security practices suggest a low risk of exploitation. However, the complete lack of nonce checks across all (non-existent) entry points, while not an immediate risk due to the absence of those entry points, could be a concern if the plugin were to evolve and introduce them without this security measure.

In conclusion, this plugin appears to be very secure, with a clean bill of health in its static analysis and vulnerability history. The developers have adhered to several key security best practices. The only potential area for slight improvement, which is not a current risk, would be to ensure nonce checks are considered if new entry points are ever added.

Key Concerns

  • No nonce checks implemented
Vulnerabilities
None known

Valentine’s Day Hearts Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Valentine’s Day Hearts Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
10 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped10 total outputs
Attack Surface

Valentine’s Day Hearts Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
filterplugin_row_metaincludes\developer.php:2
actionadmin_initincludes\settings.php:32
actionadmin_menuincludes\settings.php:102
actionwp_footerincludes\valentines-hearts.php:10
Maintenance & Trust

Valentine’s Day Hearts Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedMay 25, 2018
PHP min version
Downloads7K

Community Trust

Rating100/100
Number of ratings2
Active installs100
Developer Profile

Valentine’s Day Hearts Developer Profile

Digitally Cultured

2 plugins · 100 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Valentine’s Day Hearts

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/valentines-day-floating-hearts/assets/css/font-awesome.min.css

HTML / DOM Fingerprints

CSS Classes
dcfadcfa-heart
HTML Comments
<!-- xmas_heart [ start ] --><!-- valentines_heart [ end ] -->
Data Attributes
data-heartmaxdata-heartcolordata-hearttypedata-heartletterdata-sinkspeeddata-heartmaxsize+2 more
JS Globals
heartmaxheartcolorhearttypeheartlettersinkspeedheartmaxsize+16 more
FAQ

Frequently Asked Questions about Valentine’s Day Hearts