My Hello Dolly Security & Risk Analysis

wordpress.org/plugins/my-hello-dolly

This plugin make you custom lyrics, quotes or any other words in the upper right of your admin screen on every page, like Hello Dolly plugin.

10 active installs v1.0.0 PHP + WP 3.5+ Updated May 4, 2014
admin-noticesfunnyhell-dolly
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is My Hello Dolly Safe to Use in 2026?

Generally Safe

Score 85/100

My Hello Dolly has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The "my-hello-dolly" plugin v1.0.0 exhibits a generally strong security posture based on the provided static analysis. The plugin demonstrates good practices by avoiding dangerous functions, implementing prepared statements for all SQL queries, and including a nonce check for its single AJAX handler. The absence of file operations and external HTTP requests also contributes positively to its security. However, a notable area for concern is the complete lack of capability checks for its AJAX handler. This means that any authenticated user, regardless of their role, can trigger this functionality, potentially leading to unintended consequences if the handler performs sensitive actions. The plugin's vulnerability history is clean, with no recorded CVEs, which is a positive indicator. This suggests a lack of known exploitable issues. In conclusion, while the plugin excels in several key security areas, the absence of role-based access control on its entry point is a significant weakness that needs to be addressed to further harden its security.

Key Concerns

  • Missing capability checks on AJAX handler
  • Some output not properly escaped
Vulnerabilities
None known

My Hello Dolly Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

My Hello Dolly Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
4 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

67% escaped6 total outputs
Attack Surface

My Hello Dolly Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_my_hello_dolly_clearmy-hello.php:198
WordPress Hooks 6
actionadmin_noticesmy-hello.php:48
actionadmin_headmy-hello.php:74
actionadmin_menumy-hello.php:84
actionadmin_initmy-hello.php:135
actionadmin_print_footer_scriptsmy-hello.php:183
actionplugins_loadedmy-hello.php:220
Maintenance & Trust

My Hello Dolly Maintenance & Trust

Maintenance Signals

WordPress version tested3.9.40
Last updatedMay 4, 2014
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

My Hello Dolly Developer Profile

wphigh

3 plugins · 180 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect My Hello Dolly

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
my-hello-dolly-clear
Data Attributes
name="my_hello_dolly"id="my-hello-dolly-clear"name="my_hello_dolly_clear_nonce"id="my-hello"
JS Globals
ajaxurl
FAQ

Frequently Asked Questions about My Hello Dolly