Finally Free Support Security & Risk Analysis

wordpress.org/plugins/finally-free-support

Free WordPress support for small business owners. Live chat, support tickets, consulting calls.

0 active installs v2.0.3 PHP 5.6+ WP 4.5+ Updated Dec 1, 2018
helphelp-desksupport
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Finally Free Support Safe to Use in 2026?

Generally Safe

Score 85/100

Finally Free Support has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The 'finally-free-support' plugin v2.0.3 exhibits a strong security posture based on the provided static analysis. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events significantly limits its attack surface. Furthermore, the code demonstrates good practices with a high percentage of properly escaped output, the exclusive use of prepared statements for SQL queries, and the presence of nonce and capability checks. The lack of any file operations or external HTTP requests further reduces potential vulnerabilities.

While the static analysis reveals no direct security vulnerabilities such as dangerous functions or critical taint flows, two flows with unsanitized paths were identified. Although these did not escalate to critical or high severity, they represent a potential area for concern that warrants further investigation. The plugin's vulnerability history is exceptionally clean, with no recorded CVEs, which is a very positive indicator of its security development and maintenance. This history, combined with the positive static analysis findings, suggests a mature and secure plugin.

In conclusion, 'finally-free-support' v2.0.3 appears to be a highly secure plugin with a minimal attack surface and excellent coding practices. The identified unsanitized paths are the only minor point of concern, and their lack of escalation to higher severity mitigates immediate risk. The plugin's strong track record and absence of known vulnerabilities further solidify its good security standing.

Key Concerns

  • Flows with unsanitized paths
Vulnerabilities
None known

Finally Free Support Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Finally Free Support Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
18
88 escaped
Nonce Checks
5
Capability Checks
13
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

83% escaped106 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
swsffs_settings_page (includes\pages\settings.php:6)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Finally Free Support Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 31
actioninitincludes\class-tgm-plugin-activation.php:268
filterload_textdomain_mofileincludes\class-tgm-plugin-activation.php:269
actioninitincludes\class-tgm-plugin-activation.php:272
actionadmin_menuincludes\class-tgm-plugin-activation.php:421
actionadmin_headincludes\class-tgm-plugin-activation.php:422
filterinstall_plugin_complete_actionsincludes\class-tgm-plugin-activation.php:425
filterupdate_plugin_complete_actionsincludes\class-tgm-plugin-activation.php:426
actionadmin_noticesincludes\class-tgm-plugin-activation.php:429
actionadmin_initincludes\class-tgm-plugin-activation.php:430
actionadmin_enqueue_scriptsincludes\class-tgm-plugin-activation.php:431
actionload-plugins.phpincludes\class-tgm-plugin-activation.php:436
actionswitch_themeincludes\class-tgm-plugin-activation.php:439
actionswitch_themeincludes\class-tgm-plugin-activation.php:442
actionadmin_initincludes\class-tgm-plugin-activation.php:447
actionswitch_themeincludes\class-tgm-plugin-activation.php:452
actionload_textdomain_mofileincludes\class-tgm-plugin-activation.php:475
filterupgrader_source_selectionincludes\class-tgm-plugin-activation.php:889
actionplugins_loadedincludes\class-tgm-plugin-activation.php:2112
filtertgmpa_table_data_itemsincludes\class-tgm-plugin-activation.php:2236
filterupgrader_source_selectionincludes\class-tgm-plugin-activation.php:2977
actionadmin_initincludes\class-tgm-plugin-activation.php:3147
actionupgrader_process_completeincludes\class-tgm-plugin-activation.php:3242
filterupgrader_post_installincludes\class-tgm-plugin-activation.php:3301
filterupgrader_post_installincludes\class-tgm-plugin-activation.php:3446
actionadmin_initincludes\settings.php:20
actionadmin_menuincludes\settings.php:38
actionadmin_noticesincludes\settings.php:67
filterplugin_row_metaincludes\settings.php:88
filterplugin_action_linksincludes\settings.php:107
actionadmin_enqueue_scriptsincludes\settings.php:126
actiontgmpa_registerincludes\settings.php:186
Maintenance & Trust

Finally Free Support Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedDec 1, 2018
PHP min version5.6
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Finally Free Support Developer Profile

stoute

2 plugins · 200 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Finally Free Support

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/finally-free-support/css/style.css/wp-content/plugins/finally-free-support/js/custom.js/wp-content/plugins/finally-free-support/vendor/tgm/class-tgm-plugin-activation.php/wp-content/plugins/finally-free-support/vendor/tgm/helper.php
Script Paths
/wp-content/plugins/finally-free-support/js/custom.js
Version Parameters
finally-free-support/css/style.css?ver=finally-free-support/js/custom.js?ver=tgm/class-tgm-plugin-activation.php?ver=tgm/helper.php?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- Exit is accessed directly --><!-- Add Includes -->/** * Plugin installation and activation for WordPress themes. * ... (content of TGM-Plugin-Activation header) ... */
FAQ

Frequently Asked Questions about Finally Free Support