
Hurrakify Security & Risk Analysis
wordpress.org/plugins/hurrakifyHurrakify adds tooltips in Plain Language to your blog articles.
Is Hurrakify Safe to Use in 2026?
Generally Safe
Score 98/100Hurrakify has a strong security track record. Known vulnerabilities have been patched promptly.
The 'hurrakify' plugin v8.0.1 presents a mixed security posture. While it shows strengths in its handling of SQL queries and output escaping, significant concerns arise from its unprotected entry points. The presence of two AJAX handlers without authentication checks creates a direct attack surface, allowing potentially unauthorized actions. Furthermore, the taint analysis reveals two flows with unsanitized paths, although these did not escalate to critical or high severity vulnerabilities in this scan. The plugin's vulnerability history, though currently clear of unpatched issues, does indicate a past high-severity vulnerability related to Server-Side Request Forgery (SSRF), suggesting a pattern of potential weaknesses that require ongoing vigilance. Despite good practices in some areas, the unprotected AJAX endpoints are a notable security risk that needs immediate attention.
Key Concerns
- AJAX handlers without authentication checks
- Flows with unsanitized paths found
- No nonce checks on entry points
- No capability checks on entry points
- Past high-severity SSRF vulnerability
Hurrakify Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Hurrakify <= 2.4 - Unauthenticated Server-Side Request Forgery
Hurrakify Code Analysis
Output Escaping
Data Flow Analysis
Hurrakify Attack Surface
AJAX Handlers 2
WordPress Hooks 8
Scheduled Events 1
Maintenance & Trust
Hurrakify Maintenance & Trust
Maintenance Signals
Community Trust
Hurrakify Alternatives
BuddyPress Docs
buddypress-docs
Adds collaborative Docs to BuddyPress.
weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot
wedocs
Build AI-powered documentation hub with knowledge base, docs, wiki tools and chatbot support with weDocs, built by weDevs with 13 years of innovation.
Knowledge Base documentation & wiki plugin – BasePress Docs
basepress
Easily create & manage documentation. Reduce support tickets & scale your customer support workload. This simple plugin works with any theme.
EazyDocs – AI Powered Knowledge Base, Wiki, Documentation & FAQ Builder
eazydocs
Build professional knowledge bases with unlimited docs, drag-and-drop editor, live search, and SEO optimization.
Yada Wiki
yada-wiki
Yada Wiki is a simple wiki for your WordPress site.
Hurrakify Developer Profile
1 plugin · 80 total installs
How We Detect Hurrakify
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/hurrakify/lib/tooltipster/css/tooltipster.css/wp-content/plugins/hurrakify/lib/tooltipster/js/jquery.tooltipster.js/wp-content/plugins/hurrakify/javascript/hurraki_tooltip_script.js/wp-content/plugins/hurrakify/lib/tooltipster/js/jquery.tooltipster.js/wp-content/plugins/hurrakify/javascript/hurraki_tooltip_script.jshurrakify/lib/tooltipster/css/tooltipster.css?ver=hurrakify/lib/tooltipster/js/jquery.tooltipster.js?ver=hurrakify/javascript/hurraki_tooltip_script.js?ver=HTML / DOM Fingerprints
hurraki_tooltipdata-titlehurraki_tooltiphurraki/wp-json/hurraki_tooltip_proxy