Humans Dot Txt Security & Risk Analysis

wordpress.org/plugins/humans-dot-txt

This plugin will add a dynamic humans.txt file generated from a template that you'll define yourself.

10 active installs v1.1.1 PHP + WP 2.7.0+ Updated Jul 5, 2013
humans-txt
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Humans Dot Txt Safe to Use in 2026?

Generally Safe

Score 85/100

Humans Dot Txt has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12yr ago
Risk Assessment

The "humans-dot-txt" plugin version 1.1.1 exhibits a strong security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the potential attack surface. The code also demonstrates good practices with all SQL queries utilizing prepared statements and a high percentage of outputs being properly escaped. The presence of a nonce check and file operation, while noted, does not inherently indicate a risk without further context from taint analysis.

The taint analysis revealing zero flows with unsanitized paths and no critical or high severity issues is a positive indicator. Furthermore, the plugin has no recorded vulnerability history, including CVEs of any severity. This lack of historical vulnerabilities, combined with the clean static analysis, suggests a well-maintained and secure codebase.

Overall, the plugin appears to be secure with a minimal attack surface and no identified vulnerabilities or concerning code patterns. The strengths lie in its limited entry points, secure data handling practices (prepared statements, proper escaping), and clean vulnerability history. The primary area for potential concern, albeit minor based on the data, is the single file operation and the single nonce check, which would ideally be paired with capability checks to fully lock down functionality. However, without any identified exploits or vulnerabilities, these remain theoretical concerns at this point.

Key Concerns

  • File operation detected
  • Nonce check present, but no capability checks visible
Vulnerabilities
None known

Humans Dot Txt Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Humans Dot Txt Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
19 escaped
Nonce Checks
1
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

86% escaped22 total outputs
Attack Surface

Humans Dot Txt Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actioninithumans-dot-txt.php:41
actionadmin_menusrc\Plugin.php:30
actionadmin_initsrc\Plugin.php:31
actionwp_headsrc\Plugin.php:35
Maintenance & Trust

Humans Dot Txt Maintenance & Trust

Maintenance Signals

WordPress version tested3.6.1
Last updatedJul 5, 2013
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Humans Dot Txt Developer Profile

Rickard Andersson

4 plugins · 4K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Humans Dot Txt

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/humans-dot-txt/css/main.css/wp-content/plugins/humans-dot-txt/js/main.min.js
Script Paths
/wp-content/plugins/humans-dot-txt/js/vendor/jquery.autogrow.js/wp-content/plugins/humans-dot-txt/js/src/main.js
Version Parameters
humans-dot-txt/js/vendor/jquery.autogrow.js?ver=humans-dot-txt/js/src/main.js?ver=humans-dot-txt/js/main.min.js?ver=humans-dot-txt/css/main.css?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Humans Dot Txt