LH Personalised Content Security & Risk Analysis

wordpress.org/plugins/lh-personalised-content

This plugin allows one to personalise wordpress emails, or content for a logged in user.

10 active installs v1.31 PHP + WP 3.0+ Updated Nov 30, 2015
emailsfirst-namenamepersonalisepersonalizesender
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is LH Personalised Content Safe to Use in 2026?

Generally Safe

Score 85/100

LH Personalised Content has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The "lh-personalised-content" plugin v1.31 exhibits a strong security posture based on the provided static analysis. The code demonstrates excellent adherence to secure coding practices, with no dangerous functions, 100% usage of prepared statements for SQL queries, and 100% proper output escaping. The absence of file operations, external HTTP requests, and identified taint flows with unsanitized paths further bolster its security. The plugin's attack surface is minimal, consisting of a single shortcode, and importantly, there are no unprotected entry points. The lack of recorded vulnerabilities, including critical or high severity CVEs, and the absence of common vulnerability types in its history suggest a well-maintained and secure codebase over time. While the plugin demonstrates significant strengths, the complete absence of nonce and capability checks, even on the single shortcode, represents a potential area for improvement. Although the attack surface is small and there are no current indications of exploitation, robust security often involves implementing these checks to prevent potential abuse of even limited entry points.

Key Concerns

  • Missing capability checks
  • Missing nonce checks
Vulnerabilities
None known

LH Personalised Content Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

LH Personalised Content Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

LH Personalised Content Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[lh_personalised_content] lh-personalised-content.php:239
WordPress Hooks 3
filterwp_maillh-personalised-content.php:249
actioninitlh-personalised-content.php:250
filterthe_titlelh-personalised-content.php:251
Maintenance & Trust

LH Personalised Content Maintenance & Trust

Maintenance Signals

WordPress version tested4.2.39
Last updatedNov 30, 2015
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

LH Personalised Content Developer Profile

shawfactor

77 plugins · 15K total installs

91
trust score
Avg Security Score
87/100
Avg Patch Time
7 days
View full developer profile
Detection Fingerprints

How We Detect LH Personalised Content

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

JS Globals
lh_personalised_user
Shortcode Output
[lh_personalised_content][lh_personalised_content loggedout=""]
FAQ

Frequently Asked Questions about LH Personalised Content