
Humans Dot Txt Security & Risk Analysis
wordpress.org/plugins/humans-dot-txtThis plugin will add a dynamic humans.txt file generated from a template that you'll define yourself.
Is Humans Dot Txt Safe to Use in 2026?
Generally Safe
Score 85/100Humans Dot Txt has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "humans-dot-txt" plugin version 1.1.1 exhibits a strong security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the potential attack surface. The code also demonstrates good practices with all SQL queries utilizing prepared statements and a high percentage of outputs being properly escaped. The presence of a nonce check and file operation, while noted, does not inherently indicate a risk without further context from taint analysis.
The taint analysis revealing zero flows with unsanitized paths and no critical or high severity issues is a positive indicator. Furthermore, the plugin has no recorded vulnerability history, including CVEs of any severity. This lack of historical vulnerabilities, combined with the clean static analysis, suggests a well-maintained and secure codebase.
Overall, the plugin appears to be secure with a minimal attack surface and no identified vulnerabilities or concerning code patterns. The strengths lie in its limited entry points, secure data handling practices (prepared statements, proper escaping), and clean vulnerability history. The primary area for potential concern, albeit minor based on the data, is the single file operation and the single nonce check, which would ideally be paired with capability checks to fully lock down functionality. However, without any identified exploits or vulnerabilities, these remain theoretical concerns at this point.
Key Concerns
- File operation detected
- Nonce check present, but no capability checks visible
Humans Dot Txt Security Vulnerabilities
Humans Dot Txt Code Analysis
Output Escaping
Humans Dot Txt Attack Surface
WordPress Hooks 4
Maintenance & Trust
Humans Dot Txt Maintenance & Trust
Maintenance Signals
Community Trust
Humans Dot Txt Alternatives
Humans TXT
humanstxt
Credit the people behind your website in your humans.txt file. Easy to edit, directly within WordPress.
Acknowledgify
acknowledgify
Acknowledgify lets agencies, freelancers, and developers add credits to WordPress sites via humans.txt, meta tags, and footer links.
Humans Dot Txt Developer Profile
4 plugins · 4K total installs
How We Detect Humans Dot Txt
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/humans-dot-txt/css/main.css/wp-content/plugins/humans-dot-txt/js/main.min.js/wp-content/plugins/humans-dot-txt/js/vendor/jquery.autogrow.js/wp-content/plugins/humans-dot-txt/js/src/main.jshumans-dot-txt/js/vendor/jquery.autogrow.js?ver=humans-dot-txt/js/src/main.js?ver=humans-dot-txt/js/main.min.js?ver=humans-dot-txt/css/main.css?ver=