
WP-Hyves Security & Risk Analysis
wordpress.org/plugins/wp-hyvesImport friends and Post to Hyves: a social networking website.
Is WP-Hyves Safe to Use in 2026?
Generally Safe
Score 100/100WP-Hyves has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-hyves" v1.4.0.2 plugin exhibits a concerning security posture, despite having no recorded CVEs. The static analysis reveals significant weaknesses, particularly in output escaping, where 100% of outputs are not properly escaped. This poses a high risk for cross-site scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the site. Additionally, the presence of dangerous functions like `create_function` and `unserialize` are red flags, as they can lead to remote code execution (RCE) if not handled with extreme care and proper sanitization, which appears to be lacking given the unescaped output. The taint analysis indicates all analyzed flows have unsanitized paths, though thankfully no critical or high severity issues were flagged in this specific analysis. The complete absence of nonce checks and capability checks on entry points, coupled with a lack of documented security practices, further amplifies the risk. While the plugin's lack of external HTTP requests and its use of prepared statements for SQL queries are positive aspects, they do not outweigh the severe risks associated with unescaped output and potentially dangerous function usage.
Key Concerns
- Unescaped output detected
- Dangerous functions detected (create_function, unserialize)
- No nonce checks detected
- No capability checks detected
- All taint flows have unsanitized paths
WP-Hyves Security Vulnerabilities
WP-Hyves Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
WP-Hyves Attack Surface
WordPress Hooks 25
Maintenance & Trust
WP-Hyves Maintenance & Trust
Maintenance Signals
Community Trust
WP-Hyves Alternatives
Friends
friends
Follow others via RSS and ActivityPub and read their posts on your own WordPress.
BuddyPress Extended Friendship Request
buddypress-extended-friendship-request
BuddyPress Extended Friendship Request plugin allows users to send a personalized message with the friendship requests.
Youtube Thumbnail as Featured Image
youtube-thumbnail-to-featured-image
Use a YouTube Thumbnail as a Featured Image for a WordPress Post. You only have to set a YouTue Video URL and the plugin does the rest.
Keyring Social Importers
keyring-social-importers
Import your posts/images/etc from Twitter, Instagram, Strava, and more, into your WordPress install. Own your content.
Mutual Buddies
mutual-buddies
Mutual buddies displays BuddyPress mutual friends of the logged in user & the user whose profile the user is looking at on the Profile page.
WP-Hyves Developer Profile
4 plugins · 6K total installs
How We Detect WP-Hyves
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-hyves/css/admin-header.css/wp-content/plugins/wp-hyves/css/admin-styles.css/wp-content/plugins/wp-hyves/js/admin-header.js/wp-content/plugins/wp-hyves/js/admin-script.js/wp-content/plugins/wp-hyves/js/admin-header.js/wp-content/plugins/wp-hyves/js/admin-script.jswp-hyves/css/admin-header.css?ver=wp-hyves/css/admin-styles.css?ver=wp-hyves/js/admin-header.js?ver=wp-hyves/js/admin-script.js?ver=HTML / DOM Fingerprints
wp-hyveswphyveswp_hyves