Hello Plus Security & Risk Analysis

wordpress.org/plugins/hello-plus

Hello+ is a free WordPress plugin designed to work seamlessly with Elementor’s Hello suite of themes.

80K active installs v1.7.7 PHP 7.4+ WP 6.0+ Updated Sep 18, 2025
elementorhello-plushello-themesthemeswidgets
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Hello Plus Safe to Use in 2026?

Generally Safe

Score 100/100

Hello Plus has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6mo ago
Risk Assessment

The "hello-plus" plugin v1.7.7 exhibits a strong security posture based on the provided static analysis. The complete absence of critical or high-severity issues in taint analysis, along with 100% usage of prepared statements for SQL queries and a high percentage of properly escaped outputs, indicates good coding practices. The presence of nonce and capability checks on all identified entry points (AJAX handlers and REST API routes) further reinforces this positive assessment, demonstrating a commitment to securing the plugin's attack surface. The lack of any recorded vulnerabilities in its history is also a significant positive indicator, suggesting a stable and well-maintained codebase.

While the overall security is robust, there are a few minor areas for potential improvement. The presence of two external HTTP requests, while not inherently a vulnerability, could be a point of concern if these external services were compromised or unavailable, potentially impacting the plugin's functionality. Additionally, the total number of entry points, while protected, represents a potential attack surface that could grow with future development. However, with the current implementation and historical data, the plugin appears to be secure and well-defended against common WordPress vulnerabilities.

Vulnerabilities
None known

Hello Plus Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Hello Plus Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
163 escaped
Nonce Checks
3
Capability Checks
3
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

98% escaped166 total outputs
Attack Surface

Hello Plus Attack Surface

Entry Points5
Unprotected0

AJAX Handlers 3

authwp_ajax_helloplus_setup_wizardmodules\admin\classes\ajax\setup-wizard.php:47
authwp_ajax_helloplus_forms_lite_send_formmodules\forms\components\ajax-handler.php:259
noprivwp_ajax_helloplus_forms_lite_send_formmodules\forms\components\ajax-handler.php:260

REST API Routes 2

GET/wp-json/elementor-hello-plus/v1/onboarding-settingsmodules\admin\classes\rest\onboarding-settings.php:17
GET/wp-json/elementor-hello-plus/v1/whats-newmodules\admin\classes\rest\whats-new.php:20
WordPress Hooks 66
filterelementor/image_size/get_attachment_image_htmlclasses\ehp-image.php:84
actionelementor/widgets/registerincludes\module-base.php:246
actionrest_api_initmodules\admin\classes\rest\onboarding-settings.php:227
actionrest_api_initmodules\admin\classes\rest\whats-new.php:34
filterplugin_row_metamodules\admin\components\admin-controller.php:40
actionelementor/editor/before_enqueue_scriptsmodules\admin\components\admin-controller.php:41
actionhello-plus-theme/admin-menumodules\admin\components\admin-menu-controller.php:73
actionhello-plus/initmodules\admin\components\admin-menu-controller.php:74
actionhello-plus/activatemodules\admin\components\admin-menu-controller.php:76
actionadmin_enqueue_scriptsmodules\admin\components\scripts-controller.php:74
actionadmin_enqueue_scriptsmodules\admin\components\scripts-controller.php:75
actionelementor/frontend/after_register_scriptsmodules\content\module.php:134
actionelementor/frontend/after_register_stylesmodules\content\module.php:135
actionelementor/controls/registermodules\content\module.php:136
actionelementor/editor/after_enqueue_stylesmodules\content\module.php:137
actionelementor/editor/after_enqueue_scriptsmodules\content\module.php:138
filterhello_plus/forms/field_typesmodules\forms\fields\field-base.php:90
actionelementor/preview/enqueue_scriptsmodules\forms\fields\field-base.php:92
actionelementor/element/form/section_form_fields/before_section_endmodules\forms\fields\field-base.php:94
actionelementor/frontend/after_register_scriptsmodules\forms\module.php:145
actionelementor/frontend/after_register_stylesmodules\forms\module.php:146
actionelementor/controls/registermodules\forms\module.php:147
actionelementor/editor/after_enqueue_scriptsmodules\forms\module.php:148
actionelementor/initmodules\forms\registrars\form-actions-registrar.php:38
filternav_menu_link_attributesmodules\template-parts\classes\render\header\render-navigation.php:71
filternav_menu_submenu_css_classmodules\template-parts\classes\render\header\render-navigation.php:72
filterwalker_nav_menu_start_elmodules\template-parts\classes\render\header\render-navigation.php:73
filternav_menu_item_idmodules\template-parts\classes\render\header\render-navigation.php:74
filternav_menu_link_attributesmodules\template-parts\classes\render\widget-flex-footer-render.php:350
filternav_menu_link_attributesmodules\template-parts\classes\render\widget-flex-footer-render.php:366
filternav_menu_link_attributesmodules\template-parts\classes\render\widget-footer-render.php:141
filternav_menu_link_attributesmodules\template-parts\classes\render\widget-footer-render.php:163
filterelementor/template_library/import_images/new_attachmentmodules\template-parts\classes\runners\import.php:177
filterelementor/checklist/stepsmodules\template-parts\components\checklist.php:18
actionelementor/documents/registermodules\template-parts\components\document.php:96
actionelementor/initmodules\template-parts\components\document.php:97
actionadmin_initmodules\template-parts\components\document.php:98
actionelementor/import-export/import-kitmodules\template-parts\components\import-export.php:43
actionelementor/import-export/import-kitmodules\template-parts\components\import-export.php:44
actionelementor/import-export/import-kitmodules\template-parts\components\import-export.php:47
actionelementor/import-export/export-kitmodules\template-parts\components\import-export.php:48
actionelementor/import-export/revert-kitmodules\template-parts\components\import-export.php:49
actiondisplay_post_statesmodules\template-parts\documents\ehp-document-base.php:174
actionadmin_noticesmodules\template-parts\documents\ehp-document-base.php:175
filterelementor/documents/ajax_save/return_datamodules\template-parts\documents\ehp-document-base.php:289
actionelementor/frontend/after_register_scriptsmodules\template-parts\module.php:163
actionelementor/frontend/after_register_stylesmodules\template-parts\module.php:164
actionelementor/editor/after_enqueue_stylesmodules\template-parts\module.php:165
actionelementor/editor/before_enqueue_scriptsmodules\template-parts\module.php:166
actionelementor/controls/registermodules\template-parts\module.php:167
filterwoocommerce_add_to_cart_fragmentsmodules\template-parts\module.php:168
filterelementor/image_size/get_attachment_image_htmlmodules\template-parts\widgets\ehp-widget-base.php:622
filterelementor/image_size/get_attachment_image_htmlmodules\template-parts\widgets\ehp-widget-base.php:626
filterelementor/image_size/get_attachment_image_htmlmodules\template-parts\widgets\ehp-widget-base.php:630
actionhello-plus/activatemodules\theme\components\theme-dependency.php:39
filterhello-plus-theme/settings/hello_thememodules\theme\components\theme-overrides.php:167
filterhello-plus-theme/settings/hello_stylemodules\theme\components\theme-overrides.php:168
filterhello-plus-theme/customizer/enablemodules\theme\components\theme-overrides.php:169
filterhello-plus-theme/rest/admin-configmodules\theme\components\theme-overrides.php:170
filterelementor/editor/localize_settingsmodules\theme\components\theme-overrides.php:171
filterhello-plus-theme/display-default-headermodules\theme\components\theme-overrides.php:173
filterhello-plus-theme/display-default-footermodules\theme\components\theme-overrides.php:174
filterhello-plus-theme/template-partsmodules\theme\components\theme-overrides.php:176
actionelementor/elements/categories_registeredmodules\theme\module.php:92
actionelementor/frontend/after_register_stylesmodules\theme\module.php:93
actioninitplugin.php:200
Maintenance & Trust

Hello Plus Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 18, 2025
PHP min version7.4
Downloads439K

Community Trust

Rating60/100
Number of ratings1
Active installs80K
Developer Profile

Hello Plus Developer Profile

Elementor

15 plugins · 13.2M total installs

76
trust score
Avg Security Score
95/100
Avg Patch Time
704 days
View full developer profile
Detection Fingerprints

How We Detect Hello Plus

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/hello-plus/assets/js/helloplus-onboarding.js/wp-content/plugins/hello-plus/assets/js/helloplus-whats-new.js/wp-content/plugins/hello-plus/assets/js/helloplus-zigzag-fe.js/wp-content/plugins/hello-plus/assets/css/helloplus-zigzag.css/wp-content/plugins/hello-plus/assets/css/helloplus-hero.css/wp-content/plugins/hello-plus/assets/css/helloplus-cta.css/wp-content/plugins/hello-plus/assets/css/helloplus-flex-hero.css/wp-content/plugins/hello-plus/assets/css/helloplus-contact.css+2 more
Script Paths
/wp-content/plugins/hello-plus/assets/js/helloplus-onboarding.js/wp-content/plugins/hello-plus/assets/js/helloplus-whats-new.js/wp-content/plugins/hello-plus/assets/js/helloplus-zigzag-fe.js/wp-content/plugins/hello-plus/assets/js/helloplus-control-choose-img.js
Version Parameters
ver=1.7.7

HTML / DOM Fingerprints

CSS Classes
elementor-control-choose-img
Data Attributes
data-elementor-device-mode
FAQ

Frequently Asked Questions about Hello Plus