Hum Security & Risk Analysis

wordpress.org/plugins/hum

Personal URL shortener for WordPress

600 active installs v1.3.6 PHP 5.6+ WP 3.0+ Updated Dec 7, 2025
disoshortlinkwhistle
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Hum Safe to Use in 2026?

Generally Safe

Score 100/100

Hum has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The static analysis of "hum" v1.3.6 reveals a strong security posture with no identified vulnerabilities or dangerous code patterns. The absence of AJAX handlers, REST API routes, shortcodes, and cron events indicates a very limited attack surface. Furthermore, the code signals show a clean slate: no dangerous functions, all SQL queries are prepared, all outputs are properly escaped, and there are no file operations, external HTTP requests, nonce checks, or capability checks utilized. Taint analysis also shows no critical or high severity flows. The vulnerability history is equally clean, with zero known CVEs, indicating a history of secure development and maintenance. This plugin demonstrates excellent adherence to secure coding practices, with no exploitable weaknesses apparent in the provided data.

Vulnerabilities
None known

Hum Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Hum Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped1 total outputs
Attack Surface

Hum Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 20
actioninithum.php:17
actioninithum.php:18
actionadmin_bar_menuhum.php:32
actionquery_varshum.php:34
actionparse_requesthum.php:35
filterhum_redirecthum.php:36
filterhum_redirect_ihum.php:37
filterhum_process_redirecthum.php:38
filterpre_option_hum_shortlink_basehum.php:39
filterpre_get_shortlinkhum.php:40
filtertemplate_redirecthum.php:41
filterhum_legacy_idhum.php:42
actionatom_entryhum.php:43
actionenqueue_block_editor_assetshum.php:44
actionadmin_inithum.php:47
actionadmin_menuhum.php:48
filtermanage_edit-post_columnshum.php:49
filtermanage_edit-page_columnshum.php:50
actionmanage_posts_custom_columnhum.php:51
actionmanage_pages_custom_columnhum.php:52
Maintenance & Trust

Hum Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 7, 2025
PHP min version5.6
Downloads19K

Community Trust

Rating100/100
Number of ratings8
Active installs600
Developer Profile

Hum Developer Profile

Will Norris

5 plugins · 11K total installs

96
trust score
Avg Security Score
94/100
Avg Patch Time
2 days
View full developer profile
Detection Fingerprints

How We Detect Hum

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/hum/build/index.js
Script Paths
/wp-content/plugins/hum/build/index.js
Version Parameters
hum/build/index.asset.php

HTML / DOM Fingerprints

JS Globals
_humEditorObject
FAQ

Frequently Asked Questions about Hum