Hazel Harlow Security & Risk Analysis

wordpress.org/plugins/hazel-harlow

Keep your content fresh and up-to-date with AI-powered content updates and enhancements.

0 active installs v1.6.1 PHP 7.0+ WP 5.0+ Updated Unknown
ai-contentcontent-updatehazel-harlowreviveseo
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Hazel Harlow Safe to Use in 2026?

Generally Safe

Score 100/100

Hazel Harlow has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The 'hazel-harlow' plugin version 1.6.1 demonstrates a strong security posture based on the provided static analysis. The absence of dangerous functions, raw SQL queries, and unsanitized taint flows are significant strengths. Furthermore, the plugin implements nonces and capability checks for all its AJAX handlers and has a high rate of output escaping, indicating good development practices to prevent common web vulnerabilities. The clean vulnerability history, with no recorded CVEs, further reinforces its apparent security.

While the static analysis reveals no immediate critical vulnerabilities, the presence of 10 AJAX handlers represents a notable attack surface. Although all are reported as having authentication checks, a thorough external audit would be prudent to confirm the effectiveness of these checks in real-world scenarios. The two external HTTP requests, while not inherently a vulnerability, could potentially be a vector if the remote endpoints are compromised or if the plugin doesn't handle responses securely. The lack of specific vulnerability types in its history also means it hasn't been subjected to common attack patterns, but this could also reflect its relative obscurity or a proactive security approach by its developers.

In conclusion, the 'hazel-harlow' plugin appears to be well-developed from a security perspective, with robust implementation of protective measures. The primary area for continued vigilance would be the confirmed effectiveness of its authentication mechanisms on the AJAX endpoints and the secure handling of external HTTP requests, especially given the lack of historical vulnerability data which could indicate limited real-world adversarial testing.

Key Concerns

  • High number of AJAX handlers
  • External HTTP requests made
Vulnerabilities
None known

Hazel Harlow Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Hazel Harlow Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
11
75 escaped
Nonce Checks
11
Capability Checks
11
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

87% escaped86 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
render_main_page (hazel-harlow.php:303)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Hazel Harlow Attack Surface

Entry Points10
Unprotected0

AJAX Handlers 10

authwp_ajax_preview_post_updatehazel-harlow.php:57
authwp_ajax_apply_post_updatehazel-harlow.php:58
authwp_ajax_apply_post_update_and_edithazel-harlow.php:59
authwp_ajax_preview_post_rewritehazel-harlow.php:60
authwp_ajax_apply_rewritehazel-harlow.php:61
authwp_ajax_apply_rewrite_and_edithazel-harlow.php:62
authwp_ajax_get_dashboard_data_v2hazel-harlow.php:63
authwp_ajax_get_stale_posts_counthazel-harlow.php:64
authwp_ajax_schedule_bulk_updatehazel-harlow.php:67
authwp_ajax_schedule_bulk_rewritehazel-harlow.php:68
WordPress Hooks 8
actionadmin_noticeshazel-harlow.php:40
actionplugins_loadedhazel-harlow.php:45
actionadmin_menuhazel-harlow.php:48
actionadmin_inithazel-harlow.php:51
actionadmin_enqueue_scriptshazel-harlow.php:54
actionhazel_harlow_bulk_update_cronhazel-harlow.php:71
actionhazel_harlow_bulk_rewrite_cronhazel-harlow.php:72
actionadmin_noticeshazel-harlow.php:240

Scheduled Events 2

hazel_harlow_bulk_update_cron
hazel_harlow_bulk_rewrite_cron
Maintenance & Trust

Hazel Harlow Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedUnknown
PHP min version7.0
Downloads511

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Hazel Harlow Developer Profile

Infoforte

2 plugins · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Hazel Harlow

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/hazel-harlow/assets/css/vendor/bootstrap.min.css/wp-content/plugins/hazel-harlow/assets/css/vendor/all.min.css/wp-content/plugins/hazel-harlow/assets/css/vendor/alertify.min.css/wp-content/plugins/hazel-harlow/assets/css/vendor/default.min.css/wp-content/plugins/hazel-harlow/assets/css/admin.css/wp-content/plugins/hazel-harlow/assets/css/hazel.css/wp-content/plugins/hazel-harlow/assets/css/dashboard.css/wp-content/plugins/hazel-harlow/assets/css/settings.css+7 more
Script Paths
/wp-content/plugins/hazel-harlow/assets/js/vendor/popper.min.js/wp-content/plugins/hazel-harlow/assets/js/vendor/bootstrap.bundle.min.js/wp-content/plugins/hazel-harlow/assets/js/vendor/alertify.min.js/wp-content/plugins/hazel-harlow/assets/js/admin.js/wp-content/plugins/hazel-harlow/assets/js/main-page.js/wp-content/plugins/hazel-harlow/assets/js/dashboard.js+1 more
Version Parameters
hazel-harlow/assets/css/vendor/bootstrap.min.css?ver=hazel-harlow/assets/css/vendor/all.min.css?ver=hazel-harlow/assets/css/vendor/alertify.min.css?ver=hazel-harlow/assets/css/vendor/default.min.css?ver=hazel-harlow/assets/css/admin.css?ver=hazel-harlow/assets/css/hazel.css?ver=hazel-harlow/assets/css/dashboard.css?ver=hazel-harlow/assets/css/settings.css?ver=hazel-harlow/assets/js/vendor/popper.min.js?ver=hazel-harlow/assets/js/vendor/bootstrap.bundle.min.js?ver=hazel-harlow/assets/js/vendor/alertify.min.js?ver=hazel-harlow/assets/js/admin.js?ver=hazel-harlow/assets/js/main-page.js?ver=hazel-harlow/assets/js/dashboard.js?ver=hazel-harlow/assets/js/settings.js?ver=

HTML / DOM Fingerprints

CSS Classes
hazel-harlow-pluginhazel-harlow-dashboard-wrapperhazel-harlow-settings-wrapperhazel-harlow-logohazel-harlow-buttonhazel-harlow-inputhazel-harlow-sectionhazel-harlow-field+4 more
HTML Comments
<!-- Hazel Harlow Plugin --><!-- Hazel Harlow Admin Menu --><!-- Hazel Harlow Settings Section --><!-- Hazel Harlow Dashboard Widget -->+1 more
Data Attributes
data-hazel-harlow-noncedata-hazel-harlow-ajax-url
JS Globals
HazelHarlowAdminHazelHarlowDashboardHazelHarlowSettings
REST Endpoints
/wp-json/hazel-harlow/v1/settings/wp-json/hazel-harlow/v1/posts/wp-json/hazel-harlow/v1/dashboard-data/wp-json/hazel-harlow/v1/stale-posts-count
Shortcode Output
[hazel_harlow_dashboard][hazel_harlow_settings_form]
FAQ

Frequently Asked Questions about Hazel Harlow