HelpShelf Security & Risk Analysis

wordpress.org/plugins/helpshelf

Short Description: Easily integrate the HelpShelf widget into your WordPress site for enhanced support and streamlined knowledge base access.

0 active installs v1.0.0 PHP 7.0+ WP 4.7+ Updated Apr 17, 2025
aiknowledge-basesearchsupport
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is HelpShelf Safe to Use in 2026?

Generally Safe

Score 92/100

HelpShelf has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The 'helpshelf' v1.0.0 plugin exhibits a strong security posture based on the provided static analysis results. The absence of any identified dangerous functions, file operations, or external HTTP requests is a positive sign. Crucially, all SQL queries are properly prepared, and all output is correctly escaped, mitigating common risks like SQL injection and cross-site scripting (XSS). The plugin also demonstrates good practices by including a nonce check, which helps prevent cross-site request forgery (CSRF) attacks. Furthermore, the lack of any historical vulnerabilities suggests a history of diligent security efforts by the developers.

While the static analysis indicates a very low risk profile, the absence of capability checks on any entry points is a notable concern. Although the current attack surface is zero, if any new entry points are introduced in future versions without proper authorization checks, this could become a significant vulnerability. The lack of any identified taint flows is also positive, but it's important to remember that static analysis might not catch all complex or logic-based vulnerabilities. Overall, the plugin is well-secured in its current state, but the missing capability checks represent a potential area for improvement.

Key Concerns

  • Missing capability checks on entry points
Vulnerabilities
None known

HelpShelf Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

HelpShelf Release Timeline

v1.0.0Current
Code Analysis
Analyzed Apr 16, 2026

HelpShelf Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
6 prepared
Unescaped Output
0
9 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared6 total queries

Output Escaping

100% escaped9 total outputs
Attack Surface

HelpShelf Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actionwp_enqueue_scriptshelpshelf.php:85
actionwp_footerhelpshelf.php:148
actionadmin_menuhelpshelf.php:176
actionadmin_inithelpshelf.php:188
actionplugins_loadedincludes/class-helpshelf.php:142
actionadmin_enqueue_scriptsincludes/class-helpshelf.php:158
actionadmin_enqueue_scriptsincludes/class-helpshelf.php:159
actionwp_enqueue_scriptsincludes/class-helpshelf.php:175
actionwp_enqueue_scriptsincludes/class-helpshelf.php:176
Maintenance & Trust

HelpShelf Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedApr 17, 2025
PHP min version7.0
Downloads402

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

HelpShelf Developer Profile

helpshelf

1 plugin · 0 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect HelpShelf

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/helpshelf/admin/js/helpshelf-admin.js/wp-content/plugins/helpshelf/admin/css/helpshelf-admin.css
Script Paths
https://s3.amazonaws.com/helpshelf-production/gen/loader/
Version Parameters
helpshelf-loader?ver=1.0.0

HTML / DOM Fingerprints

HTML Comments
<!-- HelpShelf SITE_KEY not found -->
Data Attributes
name="hpsf_site_id"id="hpsf_site_id"
JS Globals
window.HelpShelfLoaderClasswindow.HelpShelfLoader
FAQ

Frequently Asked Questions about HelpShelf