WP-HOTWords Security & Risk Analysis

wordpress.org/plugins/wp-hotwords

WP-HOTWords é o primeiro em português no repositório oficial de plugins para WordPress e ele inclui automaticamente os códigos necessários para o prog …

10 active installs v4.6.2 PHP + WP 3.0+ Updated Oct 31, 2010
brasilhotwordsintegrationmonetizacao
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP-HOTWords Safe to Use in 2026?

Generally Safe

Score 85/100

WP-HOTWords has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 15yr ago
Risk Assessment

The "wp-hotwords" v4.6.2 plugin exhibits a generally strong security posture based on the static analysis and vulnerability history provided. The complete absence of known CVEs, coupled with a lack of critical or high-severity findings in taint analysis, suggests a history of secure development or effective patching. The plugin also demonstrates good practices such as using prepared statements for all SQL queries and performing capability checks for its actions.

However, a significant concern arises from the static analysis revealing that 0% of the 48 identified output operations are properly escaped. This indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, where user-supplied or dynamically generated content might be rendered in the browser without sanitization, potentially allowing attackers to inject malicious scripts. While the attack surface is commendably small and protected, the unescaped output is a glaring weakness that could be exploited.

In conclusion, while the plugin has a clean history and avoids many common pitfalls, the widespread lack of output escaping presents a substantial security risk that needs immediate attention. The developers have a strong foundation in other areas, but this specific oversight significantly undermines the overall security.

Key Concerns

  • 0% of outputs properly escaped
Vulnerabilities
None known

WP-HOTWords Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

WP-HOTWords Release Timeline

v4.6.2Current
v4.6.1
v4.6
v4.5
v4.4.1
v4.4
v4.3.1
v4.3
v4.2
v4.1.1
v4.1
v4.0.2
v4.0.1
v4.0
v2.3
v2.2
v2.1
v2.0
v1.2
v1.1
Code Analysis
Analyzed Mar 17, 2026

WP-HOTWords Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
48
0 escaped
Nonce Checks
2
Capability Checks
4
File Operations
3
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped48 total outputs
Attack Surface

WP-HOTWords Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 16
actionadmin_noticeswp-hotwords.php:22
actionadmin_headwp-hotwords.php:23
actionadmin_menuwp-hotwords.php:24
actionadmin_menuwp-hotwords.php:25
actionwp_headwp-hotwords.php:26
actionwp_footerwp-hotwords.php:27
actionhw4wp_cronwp-hotwords.php:29
actionwp_dashboard_setupwp-hotwords.php:31
actionedit_postwp-hotwords.php:33
actionpublish_postwp-hotwords.php:34
actionsave_postwp-hotwords.php:35
actionedit_postwp-hotwords.php:37
actionpublish_postwp-hotwords.php:38
actionsave_postwp-hotwords.php:39
filterthe_contentwp-hotwords.php:44
filtercomment_textwp-hotwords.php:47

Scheduled Events 1

hw4wp_cron
Maintenance & Trust

WP-HOTWords Maintenance & Trust

Maintenance Signals

WordPress version tested3.0.5
Last updatedOct 31, 2010
PHP min version
Downloads21K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

WP-HOTWords Developer Profile

bernabauer

4 plugins · 40 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP-HOTWords

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-hotwords/jscolor/jscolor.js
Script Paths
http://adshttp://site.hotwords.com.br/parceiro6.jsp

HTML / DOM Fingerprints

CSS Classes
hw4wp_footer
HTML Comments
WP-HOTWords versão: WP-HOTWords v
Data Attributes
name="HOTWordsTxt"id="HOTWordsTxt"name="SeXyWordsTxt"id="SeXyWordsTxt"
JS Globals
jscolor
FAQ

Frequently Asked Questions about WP-HOTWords