Hello Dolly Security & Risk Analysis

wordpress.org/plugins/hello-dolly

This is not just a plugin, it symbolizes the hope and enthusiasm of an entire generation summed up in two words sung most famously by Louis Armstrong.

600K active installs v1.7.2 PHP + WP 4.6+ Updated Oct 24, 2025
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Hello Dolly Safe to Use in 2026?

Generally Safe

Score 100/100

Hello Dolly has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The plugin "hello-dolly" v1.7.2 exhibits an exceptionally strong security posture based on the provided static analysis and vulnerability history. The code analysis reveals no identified attack surface through AJAX, REST API, shortcodes, or cron events. Furthermore, there are no dangerous functions, direct SQL queries (all use prepared statements), file operations, external HTTP requests, or bundled libraries. Critically, all output is properly escaped, and there are no detected taint flows, indicating a robust approach to sanitizing and handling data. The complete absence of known CVEs and past vulnerabilities further solidifies its secure reputation. While the plugin demonstrates excellent adherence to secure coding practices, the sheer lack of any discoverable entry points or complex functionality might also imply a very limited scope. However, within its operational domain, it appears to be implemented with a high degree of security awareness and diligence. This plugin can be considered very low risk.

Vulnerabilities
None known

Hello Dolly Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Hello Dolly Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Hello Dolly Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionadmin_noticeshello.php:69
actionadmin_headhello.php:100
Maintenance & Trust

Hello Dolly Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedOct 24, 2025
PHP min version
Downloads15.3M

Community Trust

Rating88/100
Number of ratings176
Active installs600K
Alternatives

Hello Dolly Alternatives

No alternatives data available yet.

Developer Profile

Hello Dolly Developer Profile

Automattic

393 plugins · 20.8M total installs

73
trust score
Avg Security Score
91/100
Avg Patch Time
1192 days
View full developer profile
Detection Fingerprints

How We Detect Hello Dolly

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
screen-reader-text
Data Attributes
dir="ltr"
Shortcode Output
<p id="dolly"><span class="screen-reader-text">Quote from Hello Dolly song, by Jerry Herman: </span><span dir="ltr">
FAQ

Frequently Asked Questions about Hello Dolly