
LH Personalised Content Security & Risk Analysis
wordpress.org/plugins/lh-personalised-contentThis plugin allows one to personalise wordpress emails, or content for a logged in user.
Is LH Personalised Content Safe to Use in 2026?
Generally Safe
Score 85/100LH Personalised Content has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "lh-personalised-content" plugin v1.31 exhibits a strong security posture based on the provided static analysis. The code demonstrates excellent adherence to secure coding practices, with no dangerous functions, 100% usage of prepared statements for SQL queries, and 100% proper output escaping. The absence of file operations, external HTTP requests, and identified taint flows with unsanitized paths further bolster its security. The plugin's attack surface is minimal, consisting of a single shortcode, and importantly, there are no unprotected entry points. The lack of recorded vulnerabilities, including critical or high severity CVEs, and the absence of common vulnerability types in its history suggest a well-maintained and secure codebase over time. While the plugin demonstrates significant strengths, the complete absence of nonce and capability checks, even on the single shortcode, represents a potential area for improvement. Although the attack surface is small and there are no current indications of exploitation, robust security often involves implementing these checks to prevent potential abuse of even limited entry points.
Key Concerns
- Missing capability checks
- Missing nonce checks
LH Personalised Content Security Vulnerabilities
LH Personalised Content Code Analysis
LH Personalised Content Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
LH Personalised Content Maintenance & Trust
Maintenance Signals
Community Trust
LH Personalised Content Alternatives
Force First and Last Name as Display Name
force-first-last
Force the user field "display_name" to be set as the user's first and last name.
Extended User Search In WP-Admin
extended-user-search-in-wp-admin
By default WordPress in WP-admin allows users to search only by username or email id.
Enhanced User Search
enhanced-user-search
Effortlessly find users in WordPress! Search by first & last name, username, or email.
BuddyPress Real Names
buddypress-real-names
BuddyPress Real Names allows you to change the regular nickname displayed for a user to anything you want.
First name Last name
first-name-and-last-name-on-registration-page
Adds First name and Last name to registration form.
LH Personalised Content Developer Profile
77 plugins · 15K total installs
How We Detect LH Personalised Content
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
lh_personalised_user[lh_personalised_content][lh_personalised_content loggedout=""]