Help Manager Security & Risk Analysis

wordpress.org/plugins/help-manager

Create documentation for the site's authors, editors, and contributors viewable in the WordPress admin and avoid repeated "how-to" questions.

40 active installs v1.0.0 PHP 5.6+ WP 4.9+ Updated Jan 26, 2022
client-sitesclientsdocsdocumentationhelp
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Help Manager Safe to Use in 2026?

Generally Safe

Score 85/100

Help Manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The 'help-manager' plugin v1.0.0 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices in its use of prepared statements for SQL queries, proper output escaping for the vast majority of outputs, and the presence of nonce and capability checks. The absence of known vulnerabilities in its history and no recorded critical or high severity issues in taint analysis are also strong indicators of a reasonably secure codebase. The plugin also avoids external HTTP requests and file operations, further reducing its attack surface.

However, a significant concern arises from the static analysis, which reveals one AJAX handler that lacks authentication checks. This unprotected entry point represents a direct pathway for potential unauthorized actions if it handles sensitive data or functionality. While the overall vulnerability history is clean and taint analysis shows no immediate critical flows, this single unprotected AJAX handler could be exploited. The plugin's strengths in secure coding practices are commendable, but the presence of even one unprotected entry point warrants careful attention.

In conclusion, 'help-manager' v1.0.0 is largely well-developed from a security perspective, with strong adherence to secure coding principles. The vulnerability history is a clear strength, suggesting a history of careful development and maintenance. The primary weakness lies in the single unprotected AJAX endpoint, which introduces a notable risk that should be addressed. Developers should prioritize securing this entry point to further strengthen the plugin's overall security posture.

Key Concerns

  • Unprotected AJAX handler
Vulnerabilities
None known

Help Manager Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Help Manager Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
13
280 escaped
Nonce Checks
2
Capability Checks
8
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

96% escaped293 total outputs
Attack Surface
1 unprotected

Help Manager Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_wphm_docs_reorderincludes\class-main.php:214
WordPress Hooks 29
filterexport_wp_filenameadmin\class-admin.php:1529
filterqueryadmin\class-admin.php:1586
actionplugins_loadedincludes\class-main.php:142
actionadmin_enqueue_scriptsincludes\class-main.php:159
actionadmin_enqueue_scriptsincludes\class-main.php:160
actionadmin_enqueue_scriptsincludes\class-main.php:161
actioncurrent_screenincludes\class-main.php:162
actionenqueue_block_editor_assetsincludes\class-main.php:163
actioninitincludes\class-main.php:166
filterpost_type_linkincludes\class-main.php:169
filterwp_sitemaps_post_typesincludes\class-main.php:172
filterwpseo_sitemap_exclude_post_typeincludes\class-main.php:173
filterwp_insert_post_dataincludes\class-main.php:176
actionadmin_initincludes\class-main.php:179
actionadmin_initincludes\class-main.php:182
actionadmin_initincludes\class-main.php:185
actionexport_wpincludes\class-main.php:186
actionadmin_menuincludes\class-main.php:189
actionadmin_menuincludes\class-main.php:192
filterparent_fileincludes\class-main.php:195
actionadmin_bar_menuincludes\class-main.php:198
actionin_admin_headerincludes\class-main.php:201
filteradmin_footer_textincludes\class-main.php:204
filterupdate_footerincludes\class-main.php:205
filteradmin_noticesincludes\class-main.php:208
actionwp_dashboard_setupincludes\class-main.php:211
filterthe_contentincludes\class-main.php:217
filterthe_contentincludes\class-main.php:220
actionadmin_initincludes\class-main.php:223
Maintenance & Trust

Help Manager Maintenance & Trust

Maintenance Signals

WordPress version tested5.9.13
Last updatedJan 26, 2022
PHP min version5.6
Downloads2K

Community Trust

Rating100/100
Number of ratings2
Active installs40
Developer Profile

Help Manager Developer Profile

Bohemia Plugins

2 plugins · 940 total installs

94
trust score
Avg Security Score
92/100
Avg Patch Time
7 days
View full developer profile
Detection Fingerprints

How We Detect Help Manager

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/help-manager/admin/assets/css/admin-global.css/wp-content/plugins/help-manager/admin/assets/css/admin.css/wp-content/plugins/help-manager/admin/assets/css/documents.css/wp-content/plugins/help-manager/admin/libs/magnific-popup/magnific-popup.min.css/wp-content/plugins/help-manager/admin/assets/js/admin-global.js/wp-content/plugins/help-manager/admin/assets/js/admin.js/wp-content/plugins/help-manager/admin/assets/js/documents.js/wp-content/plugins/help-manager/admin/libs/magnific-popup/jquery.magnific-popup.min.js+4 more
Script Paths
/wp-content/plugins/help-manager/admin/assets/js/admin-global.js/wp-content/plugins/help-manager/admin/assets/js/admin.js/wp-content/plugins/help-manager/admin/assets/js/documents.js/wp-content/plugins/help-manager/admin/libs/magnific-popup/jquery.magnific-popup.min.js/wp-content/plugins/help-manager/admin/libs/codemirror/lib/codemirror.js/wp-content/plugins/help-manager/admin/libs/codemirror/addon/edit/matchbrackets.js+2 more
Version Parameters
help-manager-admin-global?ver=help-manager-admin?ver=help-manager-documents?ver=help-manager-magnific-popup?ver=help-manager-admin-global?ver=help-manager-admin?ver=help-manager-documents?ver=help-manager-magnific-popup?ver=help-manager-codemirror?ver=help-manager-codemirror-matchbrackets?ver=help-manager-codemirror-css?ver=help-manager-codemirror-javascript?ver=

HTML / DOM Fingerprints

CSS Classes
help-manager-document-preview
Data Attributes
data-help-docs-id
JS Globals
helpManagerAdmin
REST Endpoints
/wp-json/help-manager/v1/documents/wp-json/help-manager/v1/documents/
FAQ

Frequently Asked Questions about Help Manager