
BJH Website Assistant Security & Risk Analysis
wordpress.org/plugins/bjh-site-assistantThe WordPress plugin that provides small functions to help your website working better.
Is BJH Website Assistant Safe to Use in 2026?
Generally Safe
Score 85/100BJH Website Assistant has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "bjh-site-assistant" v1.3.1 plugin demonstrates a generally good security posture in terms of its attack surface and SQL query handling. The complete absence of AJAX handlers, REST API routes, shortcodes, and cron events with unprotected entry points is a significant strength, minimizing potential avenues for exploitation. Furthermore, all identified SQL queries utilize prepared statements, mitigating the risk of SQL injection vulnerabilities. The lack of file operations and external HTTP requests also reduces potential attack vectors. However, the analysis reveals a concerningly low percentage of properly escaped output (11%), indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. The absence of nonce checks and capability checks, particularly in the context of any potential, albeit currently unlisted, internal functionality, is another area of concern. The plugin has no recorded vulnerability history, which is positive, but this could also be due to a lack of extensive security testing or public disclosure of past issues. Overall, while the plugin excels in avoiding common entry points and secure SQL practices, the significant risk of XSS due to insufficient output escaping, combined with a lack of internal authorization checks, presents a notable weakness that requires attention.
Key Concerns
- Low output escaping percentage (11%)
- No nonce checks found
- No capability checks found
BJH Website Assistant Security Vulnerabilities
BJH Website Assistant Release Timeline
BJH Website Assistant Code Analysis
Output Escaping
BJH Website Assistant Attack Surface
WordPress Hooks 25
Maintenance & Trust
BJH Website Assistant Maintenance & Trust
Maintenance Signals
Community Trust
BJH Website Assistant Alternatives
Hide Footer Links
hide-footer-links
Hide Footer Links will try to hide all footer links and copyright info from your theme.
Top Commentators Widget
top-commentators-widget
Adds a sidebar widget to show the top commentators in your WP site. Demo: http://demo.webgrrrl.net
WP Headmaster
wp-headmaster
A simple plugin for adding, enqueuing and organising common items into the Head tag without hard-coding.
NO admin premium NAGS
no-aioseop-nags
Simply stop the abusive admin nags from All in One SEO plugin and as well from YOAST Seo! Plus: Add your own CSS to the Admin Area.
Gravatar ALT & TITLE Fix
gravatar-alt-title-fix
A simple plugin to insert missing ALT & TITLE tags into your Gravatar image. Author name sourced from Gravatar.
BJH Website Assistant Developer Profile
1 plugin · 10 total installs
How We Detect BJH Website Assistant
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bjh-site-assistant/css/bsa.css/wp-content/plugins/bjh-site-assistant/js/bsa.js/wp-content/plugins/bjh-site-assistant/css/style.css/wp-content/plugins/bjh-site-assistant/js/util.js/wp-content/plugins/bjh-site-assistant/js/bsa.js/wp-content/plugins/bjh-site-assistant/js/util.jsbjh-site-assistant/style.css?ver=bjh-site-assistant/script.js?ver=