
Admin Help Docs Security & Risk Analysis
wordpress.org/plugins/admin-help-docsSite developers and operators can easily create help documentation and notices for the admin area.
Is Admin Help Docs Safe to Use in 2026?
Generally Safe
Score 100/100Admin Help Docs has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "admin-help-docs" plugin v1.4.3.2 presents a generally positive security posture, demonstrating good practices in several key areas. The absence of known CVEs and a clean vulnerability history suggest a history of stable and secure development. The plugin also shows strength in its handling of SQL queries, exclusively using prepared statements, and a very high percentage of properly escaped output, minimizing risks of injection and cross-site scripting vulnerabilities. The presence of nonce and capability checks on entry points further enhances its security.
However, the static analysis does reveal potential areas for concern. The presence of 11 instances of the `unserialize` function is a significant red flag, as unserialization of untrusted input can lead to arbitrary object injection vulnerabilities. While the taint analysis did not reveal any unsanitized flows in this specific version, the inherent risk of `unserialize` remains. Additionally, the plugin performs file operations and makes external HTTP requests, which, if not handled with utmost care, could introduce vulnerabilities. The limited number of entry points and the fact that they are protected is a positive sign, but the overall risk is elevated by the reliance on `unserialize`.
In conclusion, while the plugin has a strong track record and good security fundamentals like prepared statements and output escaping, the use of `unserialize` introduces a notable risk that should not be overlooked. The absence of historical vulnerabilities is encouraging, but the potential for a critical issue stemming from `unserialize` remains. Users should be aware of this specific concern and ensure that any input processed by `unserialize` is rigorously validated and sanitized.
Key Concerns
- Use of unserialize function
Admin Help Docs Security Vulnerabilities
Admin Help Docs Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
Admin Help Docs Attack Surface
Shortcodes 2
WordPress Hooks 49
Maintenance & Trust
Admin Help Docs Maintenance & Trust
Maintenance Signals
Community Trust
Admin Help Docs Alternatives
Admin Expert Mode
admin-expert-mode
Allows users to hide inline documentation and help text that are geared for beginning users in the WordPress admin.
Admin Documentation
admin-documentation
Adds a simple documentation page to your WordPress admin to keep instructions, notes, and other helpful information for maintaining your website.
WP Help Docs
ilab-docs
Directly integrate markdown based help documentation for your WordPress theme or plugin into the WordPress admin for your end users and clients.
WP Help
wp-help
Site operators can create detailed, hierarchical documentation for the site's authors, editors, and contributors, viewable in the WordPress admin …
EazyDocs – AI Powered Knowledge Base, Wiki, Documentation & FAQ Builder
eazydocs
Build professional knowledge bases with unlimited docs, drag-and-drop editor, live search, and SEO optimization.
Admin Help Docs Developer Profile
12 plugins · 2K total installs
How We Detect Admin Help Docs
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/admin-help-docs/includes/admin/css/helpdocs-admin.css/wp-content/plugins/admin-help-docs/includes/admin/js/helpdocs-admin.js/wp-content/plugins/admin-help-docs/includes/admin/js/helpdocs-admin-scripts.jsincludes/admin/js/helpdocs-admin.jsincludes/admin/js/helpdocs-admin-scripts.jsadmin-help-docs/includes/admin/css/helpdocs-admin.css?ver=admin-help-docs/includes/admin/js/helpdocs-admin.js?ver=admin-help-docs/includes/admin/js/helpdocs-admin-scripts.js?ver=HTML / DOM Fingerprints
helpdocs-admin-wrap<!-- Admin Help Docs -->data-helpdocs-pagedata-helpdocs-tabhelpdocs_admin_params