
Helpgent – A better way to connect with your audiences Security & Risk Analysis
wordpress.org/plugins/helpgentThe most user-friendly conversational form plugin. Drag & drop form builder plugin to create multi step forms, contact forms, feedback & custom forms
Is Helpgent – A better way to connect with your audiences Safe to Use in 2026?
Mostly Safe
Score 72/100Helpgent – A better way to connect with your audiences is generally safe to use. 1 past CVE were resolved. Keep it updated.
The helpgent v2.2.5 plugin exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices in several areas. The vast majority of output is properly escaped, and a significant portion of SQL queries utilize prepared statements, reducing the risk of injection vulnerabilities. Furthermore, the static analysis found no dangerous functions and a relatively small attack surface, with no directly identifiable unprotected entry points. However, significant concerns arise from the plugin's vulnerability history and certain aspects of its code. The presence of one critical, unpatched CVE related to Deserialization of Untrusted Data is a major red flag, indicating a severe and persistent risk that needs immediate attention. While taint analysis found no critical or high severity flows, the two identified flows with unsanitized paths warrant further investigation, as they could potentially lead to vulnerabilities if exploited in conjunction with other factors. The plugin's file operation count is also notable, and while not explicitly flagged as risky, it's an area that often harbors vulnerabilities if not handled meticulously. The low number of nonce and capability checks, coupled with the absence of explicit permission callbacks for REST API routes (though none exist), suggests a potential for privilege escalation or unauthorized access if other security measures are bypassed or if the plugin's functionality evolves to include such endpoints without proper checks. The overall conclusion is that while the plugin has some strong security foundations, the unpatched critical vulnerability and the patterns observed in its history, particularly around deserialization, present a substantial risk that overshadows its positive attributes. Urgent remediation of the known CVE is paramount.
Key Concerns
- Unpatched Critical CVE
- Flows with unsanitized paths detected
- Low number of capability checks
- Low number of nonce checks
Helpgent – A better way to connect with your audiences Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
HelpGent <= 2.2.4 - Unauthenticated PHP Object Injection
Helpgent – A better way to connect with your audiences Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Helpgent – A better way to connect with your audiences Attack Surface
Shortcodes 3
WordPress Hooks 46
Scheduled Events 1
Maintenance & Trust
Helpgent – A better way to connect with your audiences Maintenance & Trust
Maintenance Signals
Community Trust
Helpgent – A better way to connect with your audiences Alternatives
MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor
metform
The most popular Elementor forms builder to create WordPress forms like contact forms, booking forms, feedback form, survey forms, application forms a …
NEX-Forms – Ultimate Forms Plugin for WordPress
nex-forms-express-wp-form-builder
Build beautiful responsive forms for WordPress. Contact forms, surveys, quizzes, booking forms, payments, popups & more with NEX-Forms...
Easy Form Builder by WhiteStudio — Drag & Drop Form Builder
easy-form-builder
Create flexible contact forms, survey forms, payment forms, and user authentication forms using a drag-and-drop form builder plugin for WordPress.
NEX-Forms ADD ON – Form Themes
nex-forms-form-themes-add-on
Build beautiful responsive forms for WordPress. Contact forms, surveys, quizzes, booking forms, payments, popups & more with NEX-Forms...
NEX-Forms ADD ON – Zapier Integration
nex-forms-zapier-add-on
The NEX-Forms Zapier Integration Add-on enables you to seamlessly connect your form submissions to over 10,000 apps.
Helpgent – A better way to connect with your audiences Developer Profile
15 plugins · 62K total installs
How We Detect Helpgent – A better way to connect with your audiences
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/helpgent/enqueues/register.php/wp-content/plugins/helpgent/enqueues/enqueue-common.php/wp-content/plugins/helpgent/build/js/frontend/UserDashboard/index.js/wp-content/plugins/helpgent/build/js/index.js/wp-content/plugins/helpgent/enqueues/admin-enqueue.php/wp-content/plugins/helpgent/enqueues/frontend-enqueue.phphelpgent/form/shortcodehelpgent/userdashboard/shortcodehelpgent/notificationhelpgent/adminhelpgent/record-rtchelpgent/helperhelpgent/style.css?ver=helpgent/record-rtc.js?ver=helpgent/helper.js?ver=helpgent/admin.js?ver=helpgent/notification.js?ver=helpgent/userdashboard/shortcode.js?ver=helpgent/form/shortcode.js?ver=helpgent/style.css?ver=HTML / DOM Fingerprints
helpgent_is_previewhelpgent_frontend_localization/wp-json/helpgent/[helpgent-form][helpgent_user_dashboard][helpgent_messages]