HelpfulnessMeter Security & Risk Analysis

wordpress.org/plugins/helpfulnessmeter

Improve your WordPress content easily with HelpfulnessMeter, effectively collecting feedback from your visitors.

0 active installs v1.4 PHP 7.4+ WP 6.0+ Updated Apr 2, 2025
content-improvementcontent-ratinguser-experienceuser-feedbackvote
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is HelpfulnessMeter Safe to Use in 2026?

Generally Safe

Score 92/100

HelpfulnessMeter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "helpfulnessmeter" plugin v1.4 demonstrates a strong security posture based on the static analysis. The complete absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests is commendable. Furthermore, the plugin extensively utilizes prepared statements for its single SQL query and maintains a very high rate of output escaping (98%), significantly reducing the risk of common web vulnerabilities like SQL injection and XSS. The presence of nonce checks and capability checks on its entry points further bolsters its defenses.

The vulnerability history is also remarkably clean, with no recorded CVEs across any severity level. This suggests a history of secure development practices and diligent maintenance. The lack of critical or high-severity taint flows reinforces the impression that data handling within the plugin is robust.

Overall, "helpfulnessmeter" v1.4 appears to be a secure plugin with minimal inherent risks. Its strengths lie in its proactive approach to security through proper sanitization, escaping, and authentication checks on its limited attack surface. The absence of any past vulnerabilities is a significant positive indicator.

Vulnerabilities
None known

HelpfulnessMeter Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

HelpfulnessMeter Release Timeline

v1.4Current
v1.3
v1.2.2
v1.2.1
v1.2
v1.1.1
v1.1
v1.0.2
v1.0.1
v1.0
Code Analysis
Analyzed Apr 16, 2026

HelpfulnessMeter Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
2
82 escaped
Nonce Checks
2
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

98% escaped84 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
hfnm_options_page (helpfulnessmeter.php:274)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

HelpfulnessMeter Attack Surface

Entry Points4
Unprotected0

AJAX Handlers 2

authwp_ajax_hfnm_ajaxhelpfulnessmeter.php:30
noprivwp_ajax_hfnm_ajaxhelpfulnessmeter.php:31

Shortcodes 2

[helpfulness_meter] helpfulnessmeter.php:35
[hfnm_shortcode_list] helpfulnessmeter.php:36
WordPress Hooks 7
actionadmin_noticeshelpfulnessmeter.php:25
filterplugin_action_linkshelpfulnessmeter.php:26
actionplugins_loadedhelpfulnessmeter.php:27
filterthe_contenthelpfulnessmeter.php:28
actionwp_enqueue_scriptshelpfulnessmeter.php:29
actioninithelpfulnessmeter.php:32
actionadmin_menuhelpfulnessmeter.php:33
Maintenance & Trust

HelpfulnessMeter Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedApr 2, 2025
PHP min version7.4
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

HelpfulnessMeter Developer Profile

Ludovic S. Clain

3 plugins · 20 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect HelpfulnessMeter

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/helpfulnessmeter/css/style.css/wp-content/plugins/helpfulnessmeter/js/script.js
Script Paths
/wp-content/plugins/helpfulnessmeter/js/script.js
Version Parameters
helpfulnessmeter/css/style.css?ver=helpfulnessmeter/js/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
hfnm-titlehfnm-yes-nohfnm-thank-yeshfnm-thank-no
Data Attributes
data-post-iddata-value
JS Globals
hfnmData
Shortcode Output
<div id="helpfulnessmeter"<div id="hfnm-title"><div id="hfnm-yes-no"><span data-value="1">
FAQ

Frequently Asked Questions about HelpfulnessMeter