
WODHOPPER Security & Risk Analysis
wordpress.org/plugins/wodhopperEasily embed, manage and configure WODHOPPER into WordPress.
Is WODHOPPER Safe to Use in 2026?
Generally Safe
Score 85/100WODHOPPER has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wodhopper" plugin version 1.0.6 presents a mixed security posture. On the positive side, static analysis reveals no dangerous functions, file operations, or external HTTP requests, and all SQL queries utilize prepared statements. The plugin also demonstrates some good practices by including capability checks and bundling the TinyMCE library, which is standard. The absence of known vulnerabilities (CVEs) in its history is a strong indicator of past security diligence.
However, a significant concern arises from the complete lack of output escaping across all identified output points. This means that any dynamic content generated by the plugin, if it originates from user-supplied input or external sources, is not being properly sanitized before being displayed. This creates a high risk for Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the website that could then be executed by other users. The lack of nonce checks, while not directly tied to a specific entry point in this analysis, is generally a good practice for preventing Cross-Site Request Forgery (CSRF) attacks on AJAX actions.
In conclusion, while the plugin shows strength in its handling of SQL and absence of known vulnerabilities, the critical flaw of unescaped output represents a substantial risk that needs immediate attention. The plugin's attack surface is minimal, but the vulnerability within that surface is significant.
Key Concerns
- All identified outputs are unescaped
- No nonce checks on any entry points
WODHOPPER Security Vulnerabilities
WODHOPPER Release Timeline
WODHOPPER Code Analysis
Bundled Libraries
Output Escaping
WODHOPPER Attack Surface
Shortcodes 1
WordPress Hooks 7
Maintenance & Trust
WODHOPPER Maintenance & Trust
Maintenance Signals
Community Trust
WODHOPPER Alternatives
WP WDFY Integration of Wodify
wp-wdfy-integration-of-wodify
Display Wodify information directly within your Wordpress blog.
embedbolcom
embedbolcom
Registers embedbol.com as an oEmbed provider allowing for easy embedding of products from bol.com.
Katalys Shops Addon: Merchant Bridge
katalys-shop
Provides automatic order fulfillment integration with Katalys Shop orders for WooCommerce.
Rexultz Product Feeds
rexultz-product-feeds
Embed Rexultz product feeds using shortcodes or the Gutenberg block editor with server-side rendering.
WODTogether Whiteboards
wodtogether-whiteboards
Allows embedding of WODTogether whiteboards into your blog posts automatically.
WODHOPPER Developer Profile
1 plugin · 10 total installs
How We Detect WODHOPPER
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wodhopper/assets/css/wodhopper_scoreboard_styles.csshttp://app.wodhopper.com/js/wodhopper.jsHTML / DOM Fingerprints
[wodhopper_scoreboard_button placement="" wod_date=""]