
Humans TXT Security & Risk Analysis
wordpress.org/plugins/humanstxtCredit the people behind your website in your humans.txt file. Easy to edit, directly within WordPress.
Is Humans TXT Safe to Use in 2026?
Generally Safe
Score 85/100Humans TXT has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The humansTXT plugin v1.3.1 exhibits a mixed security posture. While it has no recorded vulnerabilities (CVEs) and a lack of dangerous file operations or external HTTP requests are positive signs, several areas warrant concern. The presence of an unprotected AJAX handler represents a significant attack vector, as it lacks authentication checks, making it potentially exploitable by unauthenticated users. Furthermore, the plugin utilizes raw SQL queries without prepared statements, which can lead to SQL injection vulnerabilities if user input is not properly sanitized. The taint analysis reveals that all four analyzed flows have unsanitized paths, though thankfully none are classified as critical or high severity. However, this indicates a potential for data to be mishandled. The limited number of entry points is a positive, but the unprotected AJAX handler significantly increases the risk profile. Overall, the plugin has some good security practices but suffers from critical vulnerabilities in authentication and SQL handling.
Key Concerns
- Unprotected AJAX handler
- SQL queries without prepared statements
- Unsanitized paths in taint flows
- Low output escaping percentage
Humans TXT Security Vulnerabilities
Humans TXT Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Humans TXT Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 15
Maintenance & Trust
Humans TXT Maintenance & Trust
Maintenance Signals
Community Trust
Humans TXT Alternatives
Acknowledgify
acknowledgify
Acknowledgify lets agencies, freelancers, and developers add credits to WordPress sites via humans.txt, meta tags, and footer links.
Humans Dot Txt
humans-dot-txt
This plugin will add a dynamic humans.txt file generated from a template that you'll define yourself.
Digital Humans
digital-humans
UNITH Digital Humans are personalized, real-time conversational assistants. Use this plugin to add a UNITH Digital Human to your website.
HumanCaptcha by Outerbridge
humancaptcha
HumanCaptcha is a Captcha that uses questions that require human logic to answer them to the WordPress login form, comments form and registration form …
WP-HR Manager: The Human Resources Plugin for WordPress
wp-hr-manager
Easily add a powerful HR / human resource management system and employee self service (ESS) portal to your website. = Credits = This plugin uses [WP E …
Humans TXT Developer Profile
5 plugins · 411K total installs
How We Detect Humans TXT
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/humanstxt/css/humans.css/wp-content/plugins/humanstxt/js/humans.js/wp-content/plugins/humanstxt/js/humans.jshumanstxt/css/humans.css?ver=humanstxt/js/humans.js?ver=HTML / DOM Fingerprints
humanstxthumanstxt-headlinedata-humanstxt-idwindow.humans[humanstxt][humanstxt pre="1"][humanstxt plain="1"][humanstxt wrap="0"]