
LetMeHelp – Support & Help Desk Assistant Security & Risk Analysis
wordpress.org/plugins/letmehelpA WordPress plugin that streamlines the contact process by providing possible solutions to common issues, reducing support requests and improving user …
Is LetMeHelp – Support & Help Desk Assistant Safe to Use in 2026?
Generally Safe
Score 85/100LetMeHelp – Support & Help Desk Assistant has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "letmehelp" plugin v1.0.2 demonstrates several strong security practices, particularly in its diligent use of prepared statements for SQL queries and robust output escaping, with 100% of outputs being properly escaped. The plugin also shows a good understanding of WordPress security by implementing capability checks on a significant portion of its entry points.
However, a notable concern arises from the presence of a REST API route that lacks a permission callback. This means that this specific endpoint is accessible without proper authentication or authorization, potentially exposing it to unauthorized access or manipulation depending on its functionality. The absence of any recorded vulnerabilities or CVEs in its history is a positive indicator of good development, but this should not overshadow the immediate risk presented by the unprotected REST API endpoint.
Overall, the plugin has a solid foundation with its secure coding practices. The primary weakness lies in the single unprotected REST API route, which represents a clear attack vector. Addressing this specific oversight is crucial to significantly improve its security posture. Without this, the plugin can be considered moderately secure, but with a distinct area of risk.
Key Concerns
- Unprotected REST API route without permission callback
- No nonce checks implemented
LetMeHelp – Support & Help Desk Assistant Security Vulnerabilities
LetMeHelp – Support & Help Desk Assistant Code Analysis
SQL Query Safety
Output Escaping
LetMeHelp – Support & Help Desk Assistant Attack Surface
REST API Routes 12
WordPress Hooks 6
Maintenance & Trust
LetMeHelp – Support & Help Desk Assistant Maintenance & Trust
Maintenance Signals
Community Trust
LetMeHelp – Support & Help Desk Assistant Alternatives
Live Chat with Messenger Customer Chat
fb-messenger-live-chat
Support your customers via Facebook Messenger Live Chat conveniently from your own website.
Zendesk Support for WordPress
zendesk
Bring the helpdesk into your blog
Help Scout
help-scout
Release 6.5.7 License: GPLv2 or later License URI: http://www.gnu.org/licenses/gpl-2.0.html Add a contact form to your website, or embed Help Scout Be …
Re:amaze Helpdesk & Live Chat
reamaze
Boost sales conversions, loyalty, and engagement. Manage your social, email, sms, live chat, FAQ for your WordPress or WooCommerce store.
ChipBot – Video, Live Chat, & AI Help Desk
chipbot
ChipBot turns your website into a face-to-face story experience powered by AI, video, and chat.
LetMeHelp – Support & Help Desk Assistant Developer Profile
3 plugins · 120 total installs
How We Detect LetMeHelp – Support & Help Desk Assistant
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/letmehelp/build/public/css/base.css/wp-content/plugins/letmehelp/build/public/js/base.js/wp-content/plugins/letmehelp/build/settings/index.js/wp-content/plugins/letmehelp/build/settings/style-index.css/wp-content/plugins/letmehelp/build/public/js/base.js/wp-content/plugins/letmehelp/build/settings/index.jsletmehelp/build/public/css/base.css?ver=letmehelp/build/public/js/base.js?ver=letmehelp/build/settings/index.js?ver=letmehelp/build/settings/style-index.css?ver=HTML / DOM Fingerprints
letmehelpApiSettingsletmehelpApiPublic/wp-json/letmehelp/v1/links//wp-json/letmehelp/v1/links/(?P<id>\d+)/wp-json/letmehelp/v1/search-links/