
BugHerd Security & Risk Analysis
wordpress.org/plugins/bugherdBugHerd is the visual feedback tool for websites.
Is BugHerd Safe to Use in 2026?
Generally Safe
Score 100/100BugHerd has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of Bugherd v1.0.14 reveals a generally strong security posture with no identified dangerous functions, SQL injection vulnerabilities, or file operations. The absence of external HTTP requests and bundled libraries is also a positive sign. However, the analysis does highlight some areas for concern. The low percentage of properly escaped output (78%) suggests a potential for cross-site scripting (XSS) vulnerabilities, though the absence of known CVEs and taint analysis findings currently mitigates this risk. Furthermore, the complete lack of nonce checks and capability checks across all identified entry points, while currently presenting a zero attack surface, indicates a reliance on other security layers or a potential oversight in security implementation that could become a weakness if new entry points are introduced or if existing ones are exposed differently.
The plugin's vulnerability history is exceptionally clean, with no recorded CVEs. This, combined with the absence of critical or high severity taint flows, suggests a history of secure development practices or effective patching. While the lack of explicit capability checks is a noted weakness, the overall lack of identified vulnerabilities and the absence of critical code signals indicate that the plugin is likely safe to use in its current version. The primary recommendation would be to investigate and improve output escaping to reach 100% to proactively address potential XSS risks.
Key Concerns
- Low percentage of properly escaped output
- No nonce checks across entry points
- No capability checks across entry points
BugHerd Security Vulnerabilities
BugHerd Code Analysis
Output Escaping
BugHerd Attack Surface
WordPress Hooks 4
Maintenance & Trust
BugHerd Maintenance & Trust
Maintenance Signals
Community Trust
BugHerd Alternatives
IthStatsWP Client
ithstatswp-client
Install this plugin on unlimited sites and manage them all from a central dashboard.
Website Diary
website-diary
For keeping diary-like notes, so you can quickly overview recent changes on your site (and spot the source of an eventual problem).
WP Site Monitor
wp-site-monitor
Extends official WP REST API to provide extra endpoints to help manage sites remotely.
WPSupervisor Client
wpsupervisor-client
Install this plugin on unlimited sites and manage them all from a central dashboard. This plugin communicates with your WPSupervisor Admin Panel.
UserView
userview
Logs user activities like profile updates, additions, and deletions, offering a dashboard for easy viewing and management.
BugHerd Developer Profile
1 plugin · 3K total installs
How We Detect BugHerd
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
https://www.bugherd.com/sidebarv2.js