Hello Dolly For Your Song Security & Risk Analysis

wordpress.org/plugins/hello-dolly-for-your-song

This simple plugin shows a random line of any text in your blog.

60 active installs v0.20 PHP 7.0+ WP 5.2+ Updated Sep 4, 2025
adminhello-worldlearning-wordpressloverandom
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Hello Dolly For Your Song Safe to Use in 2026?

Generally Safe

Score 100/100

Hello Dolly For Your Song has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7mo ago
Risk Assessment

The "hello-dolly-for-your-song" plugin v0.20 exhibits a mixed security posture. On the positive side, it demonstrates good practices by avoiding dangerous functions, file operations, external HTTP requests, and has zero known CVEs, indicating a generally well-maintained codebase. The absence of SQL injection vulnerabilities due to the use of prepared statements is also a significant strength.

However, there are notable security concerns stemming from the static analysis. The presence of a REST API route without proper permission callbacks creates a significant attack surface that could be exploited by unauthenticated users. Furthermore, the lack of nonce checks and capability checks for any entry points leaves it vulnerable to various types of attacks, such as Cross-Site Request Forgery (CSRF) if user interactions are involved. The significant portion of improperly escaped output (39%) also poses a risk for Cross-Site Scripting (XSS) vulnerabilities.

Given the clean vulnerability history, it's possible that the identified weaknesses have not been actively exploited yet. However, the unprotected REST API endpoint and the general lack of authentication and authorization checks on entry points represent a clear and present risk that should be addressed. While the plugin has strengths in avoiding common pitfalls like raw SQL and dangerous functions, these fundamental security oversights require immediate attention to improve its overall security.

Key Concerns

  • REST API route without permission callbacks
  • Unprotected entry points (1/2)
  • Lack of nonce checks
  • Lack of capability checks
  • Significant improperly escaped output (39%)
Vulnerabilities
None known

Hello Dolly For Your Song Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Hello Dolly For Your Song Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
11 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

61% escaped18 total outputs
Attack Surface
1 unprotected

Hello Dolly For Your Song Attack Surface

Entry Points2
Unprotected1

REST API Routes 1

GET/wp-json/restful-hello-dolly-for-your-song/texthdfys_rest.php:55

Shortcodes 1

[hdfys] hdfys_shortcode.php:32
WordPress Hooks 12
actionadmin_noticeshdfys_display.php:38
actionadmin_headhdfys_display.php:97
actionenqueue_block_editor_assetshdfys_gutenberg.php:75
actionrest_api_inithdfys_rest.php:48
actioninithdfys_rest.php:89
actionadmin_inithdfys_settings.php:87
actionadmin_menuhdfys_settings.php:110
filtersite_status_testshdfys_sitehealth.php:33
filterdebug_informationhdfys_sitehealth.php:121
actionplugins_loadedhdfys_translations.php:25
actionplugins_loadedhdfys_update.php:86
actionwidgets_inithdfys_widget.php:79
Maintenance & Trust

Hello Dolly For Your Song Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 4, 2025
PHP min version7.0
Downloads7K

Community Trust

Rating0/100
Number of ratings0
Active installs60
Developer Profile

Hello Dolly For Your Song Developer Profile

unmus

2 plugins · 90 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Hello Dolly For Your Song

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/hello-dolly-for-your-song/block.js
Script Paths
/wp-content/plugins/hello-dolly-for-your-song/block.js

HTML / DOM Fingerprints

CSS Classes
hdfysgutenberg-blockshortcode
JS Globals
hdfysParams
REST Endpoints
/restful-hello-dolly-for-your-song/text
Shortcode Output
<p class="hdfys shortcode">
FAQ

Frequently Asked Questions about Hello Dolly For Your Song