
Help Manager Security & Risk Analysis
wordpress.org/plugins/help-managerCreate documentation for the site's authors, editors, and contributors viewable in the WordPress admin and avoid repeated "how-to" questions.
Is Help Manager Safe to Use in 2026?
Generally Safe
Score 85/100Help Manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'help-manager' plugin v1.0.0 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices in its use of prepared statements for SQL queries, proper output escaping for the vast majority of outputs, and the presence of nonce and capability checks. The absence of known vulnerabilities in its history and no recorded critical or high severity issues in taint analysis are also strong indicators of a reasonably secure codebase. The plugin also avoids external HTTP requests and file operations, further reducing its attack surface.
However, a significant concern arises from the static analysis, which reveals one AJAX handler that lacks authentication checks. This unprotected entry point represents a direct pathway for potential unauthorized actions if it handles sensitive data or functionality. While the overall vulnerability history is clean and taint analysis shows no immediate critical flows, this single unprotected AJAX handler could be exploited. The plugin's strengths in secure coding practices are commendable, but the presence of even one unprotected entry point warrants careful attention.
In conclusion, 'help-manager' v1.0.0 is largely well-developed from a security perspective, with strong adherence to secure coding principles. The vulnerability history is a clear strength, suggesting a history of careful development and maintenance. The primary weakness lies in the single unprotected AJAX endpoint, which introduces a notable risk that should be addressed. Developers should prioritize securing this entry point to further strengthen the plugin's overall security posture.
Key Concerns
- Unprotected AJAX handler
Help Manager Security Vulnerabilities
Help Manager Code Analysis
Output Escaping
Help Manager Attack Surface
AJAX Handlers 1
WordPress Hooks 29
Maintenance & Trust
Help Manager Maintenance & Trust
Maintenance Signals
Community Trust
Help Manager Alternatives
WP Help
wp-help
Site operators can create detailed, hierarchical documentation for the site's authors, editors, and contributors, viewable in the WordPress admin …
Back End Instructions
back-end-instructions
Plugin for WordPress developers to provide easy "how to use" instructions to their clients.
Admin Documentation
admin-documentation
Adds a simple documentation page to your WordPress admin to keep instructions, notes, and other helpful information for maintaining your website.
WP Help Docs
ilab-docs
Directly integrate markdown based help documentation for your WordPress theme or plugin into the WordPress admin for your end users and clients.
SimpleDocs – Documentation and Knowledge Base
simpledocs
A powerful, theme-friendly documentation system that works out of the box—no bloat, no JS, just clean, structured, and styled docs.
Help Manager Developer Profile
2 plugins · 940 total installs
How We Detect Help Manager
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/help-manager/admin/assets/css/admin-global.css/wp-content/plugins/help-manager/admin/assets/css/admin.css/wp-content/plugins/help-manager/admin/assets/css/documents.css/wp-content/plugins/help-manager/admin/libs/magnific-popup/magnific-popup.min.css/wp-content/plugins/help-manager/admin/assets/js/admin-global.js/wp-content/plugins/help-manager/admin/assets/js/admin.js/wp-content/plugins/help-manager/admin/assets/js/documents.js/wp-content/plugins/help-manager/admin/libs/magnific-popup/jquery.magnific-popup.min.js+4 more/wp-content/plugins/help-manager/admin/assets/js/admin-global.js/wp-content/plugins/help-manager/admin/assets/js/admin.js/wp-content/plugins/help-manager/admin/assets/js/documents.js/wp-content/plugins/help-manager/admin/libs/magnific-popup/jquery.magnific-popup.min.js/wp-content/plugins/help-manager/admin/libs/codemirror/lib/codemirror.js/wp-content/plugins/help-manager/admin/libs/codemirror/addon/edit/matchbrackets.js+2 morehelp-manager-admin-global?ver=help-manager-admin?ver=help-manager-documents?ver=help-manager-magnific-popup?ver=help-manager-admin-global?ver=help-manager-admin?ver=help-manager-documents?ver=help-manager-magnific-popup?ver=help-manager-codemirror?ver=help-manager-codemirror-matchbrackets?ver=help-manager-codemirror-css?ver=help-manager-codemirror-javascript?ver=HTML / DOM Fingerprints
help-manager-document-previewdata-help-docs-idhelpManagerAdmin/wp-json/help-manager/v1/documents/wp-json/help-manager/v1/documents/