Assistant7 Security & Risk Analysis

wordpress.org/plugins/assistant7

Assistant7 is here to integrate with Commerce7. Helping integrate with Guest Counters and Product Reviews.

10 active installs v2.0.8 PHP + WP 5.6+ Updated Sep 7, 2022
commerce7guestcounterreviews
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Assistant7 Safe to Use in 2026?

Generally Safe

Score 85/100

Assistant7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The plugin "assistant7" v2.0.8 demonstrates a generally strong security posture based on this static analysis. The complete absence of entry points such as AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the potential attack surface. Furthermore, the analysis indicates no identified dangerous functions, no file operations, and no external HTTP requests, which are all positive indicators of secure coding practices. The use of prepared statements for all SQL queries is also a major strength, mitigating SQL injection risks.

However, there are areas for improvement. A notable concern is the 45% of output that is not properly escaped. This could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is directly reflected in the output without adequate sanitization. Additionally, the lack of any nonce checks or capability checks across all entry points (though there are zero identified entry points) suggests a potential gap in security if the plugin were to introduce such features in the future without proper authorization checks.

While the vulnerability history is clean, with no known CVEs, this does not guarantee future security. The combination of unescaped output and a lack of authorization checks, even with a minimal attack surface currently, presents a latent risk. The plugin's strengths lie in its limited attack surface and secure database interactions, but the unaddressed output escaping and absence of authorization mechanisms warrant attention for a truly robust security profile.

Key Concerns

  • Unescaped output detected
  • Missing capability checks on entry points
  • Missing nonce checks on entry points
Vulnerabilities
None known

Assistant7 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Assistant7 Release Timeline

v1.0.1
v1.0
Code Analysis
Analyzed Apr 16, 2026

Assistant7 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
17
21 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

55% escaped38 total outputs
Attack Surface

Assistant7 Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionplugins_loadedincludes/class-assistant7.php:142
actionadmin_enqueue_scriptsincludes/class-assistant7.php:157
actionadmin_enqueue_scriptsincludes/class-assistant7.php:158
actionadmin_initincludes/class-assistant7.php:161
actionadmin_menuincludes/class-assistant7.php:164
actionwp_enqueue_scriptsincludes/class-assistant7.php:183
actionwp_enqueue_scriptsincludes/class-assistant7.php:184
actionwp_enqueue_scriptspublic/class-assistant7-public.php:100
Maintenance & Trust

Assistant7 Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedSep 7, 2022
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Assistant7 Developer Profile

justingiesbrecht

2 plugins · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Assistant7

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/assistant7/css/assistant7-admin.css/wp-content/plugins/assistant7/js/assistant7-admin.js
Script Paths
js/assistant7-admin.js
Version Parameters
assistant7-admin.css?ver=assistant7-admin.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Assistant7