LetMeHelp – Support & Help Desk Assistant Security & Risk Analysis

wordpress.org/plugins/letmehelp

A WordPress plugin that streamlines the contact process by providing possible solutions to common issues, reducing support requests and improving user …

0 active installs v1.0.2 PHP 7.4+ WP 6.1+ Updated Apr 14, 2023
help-assistanthelp-deskhelp-linksmulti-step-pagesupport
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is LetMeHelp – Support & Help Desk Assistant Safe to Use in 2026?

Generally Safe

Score 85/100

LetMeHelp – Support & Help Desk Assistant has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The "letmehelp" plugin v1.0.2 demonstrates several strong security practices, particularly in its diligent use of prepared statements for SQL queries and robust output escaping, with 100% of outputs being properly escaped. The plugin also shows a good understanding of WordPress security by implementing capability checks on a significant portion of its entry points.

However, a notable concern arises from the presence of a REST API route that lacks a permission callback. This means that this specific endpoint is accessible without proper authentication or authorization, potentially exposing it to unauthorized access or manipulation depending on its functionality. The absence of any recorded vulnerabilities or CVEs in its history is a positive indicator of good development, but this should not overshadow the immediate risk presented by the unprotected REST API endpoint.

Overall, the plugin has a solid foundation with its secure coding practices. The primary weakness lies in the single unprotected REST API route, which represents a clear attack vector. Addressing this specific oversight is crucial to significantly improve its security posture. Without this, the plugin can be considered moderately secure, but with a distinct area of risk.

Key Concerns

  • Unprotected REST API route without permission callback
  • No nonce checks implemented
Vulnerabilities
None known

LetMeHelp – Support & Help Desk Assistant Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

LetMeHelp – Support & Help Desk Assistant Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
13 prepared
Unescaped Output
0
36 escaped
Nonce Checks
0
Capability Checks
11
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

93% prepared14 total queries

Output Escaping

100% escaped36 total outputs
Attack Surface
1 unprotected

LetMeHelp – Support & Help Desk Assistant Attack Surface

Entry Points12
Unprotected1

REST API Routes 12

GET/wp-json/letmehelp/v1/links/src\php\Base\Api.php:38
GET/wp-json/letmehelp/v1/links/src\php\Base\Api.php:61
GET/wp-json/letmehelp/v1/links/(?P<id>\d+)src\php\Base\Api.php:98
GET/wp-json/letmehelp/v1/links/(?P<id>\d+)src\php\Base\Api.php:129
GET/wp-json/letmehelp/v1/search-links/src\php\Base\Api.php:170
GET/wp-json/letmehelp/v1/keywords/src\php\Base\Api.php:198
GET/wp-json/letmehelp/v1/keywords/src\php\Base\Api.php:221
GET/wp-json/letmehelp/v1/keywords/(?P<id>\d+)src\php\Base\Api.php:252
GET/wp-json/letmehelp/v1/keywords/(?P<id>\d+)src\php\Base\Api.php:288
GET/wp-json/letmehelp/v1/links-keywords/src\php\Base\Api.php:319
GET/wp-json/letmehelp/v1/links-keywords/src\php\Base\Api.php:342
GET/wp-json/letmehelp/v1/links-keywords/src\php\Base\Api.php:379
WordPress Hooks 6
actionrest_api_initsrc\php\Base\Api.php:24
actionadmin_enqueue_scriptssrc\php\Base\Enqueue.php:17
actionwp_enqueue_scriptssrc\php\Base\Enqueue.php:18
actioninitsrc\php\Blocks\Base.php:22
filterquery_varssrc\php\Blocks\Base.php:23
actionadmin_menusrc\php\Pages\Admin.php:19
Maintenance & Trust

LetMeHelp – Support & Help Desk Assistant Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedApr 14, 2023
PHP min version7.4
Downloads720

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

LetMeHelp – Support & Help Desk Assistant Developer Profile

Taras Dashkevych

3 plugins · 120 total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect LetMeHelp – Support & Help Desk Assistant

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/letmehelp/build/public/css/base.css/wp-content/plugins/letmehelp/build/public/js/base.js/wp-content/plugins/letmehelp/build/settings/index.js/wp-content/plugins/letmehelp/build/settings/style-index.css
Script Paths
/wp-content/plugins/letmehelp/build/public/js/base.js/wp-content/plugins/letmehelp/build/settings/index.js
Version Parameters
letmehelp/build/public/css/base.css?ver=letmehelp/build/public/js/base.js?ver=letmehelp/build/settings/index.js?ver=letmehelp/build/settings/style-index.css?ver=

HTML / DOM Fingerprints

JS Globals
letmehelpApiSettingsletmehelpApiPublic
REST Endpoints
/wp-json/letmehelp/v1/links//wp-json/letmehelp/v1/links/(?P<id>\d+)/wp-json/letmehelp/v1/search-links/
FAQ

Frequently Asked Questions about LetMeHelp – Support & Help Desk Assistant