
NHR Core Contributions Security & Risk Analysis
wordpress.org/plugins/nhrrob-core-contributionsDisplay Core Contributions stat in your own website.
Is NHR Core Contributions Safe to Use in 2026?
Generally Safe
Score 100/100NHR Core Contributions has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "nhrrob-core-contributions" v1.3.1 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, a complete reliance on prepared statements for SQL queries, and excellent output escaping (99%) are significant strengths. The plugin also demonstrates good practices with 4 capability checks and 1 nonce check, indicating awareness of WordPress security mechanisms.
However, a key concern arises from the REST API analysis. One out of two REST API routes lacks permission callbacks, presenting an unprotected entry point. While there are no reported critical taint flows or dangerous functions, this unprotected REST API endpoint could be a target for unauthorized access or manipulation, especially if it handles sensitive data or functionality. The plugin's vulnerability history is clean, with no recorded CVEs, which is positive, but it also means there's no historical data to suggest how the developers handle security issues when they do arise.
In conclusion, the plugin has commendable security implementations in many areas. The primary weakness is the unprotected REST API endpoint. Mitigating this specific risk should be the immediate priority. The lack of historical vulnerabilities is a good sign, but ongoing vigilance and timely updates are always recommended for any plugin.
Key Concerns
- Unprotected REST API route
NHR Core Contributions Security Vulnerabilities
NHR Core Contributions Release Timeline
NHR Core Contributions Code Analysis
Output Escaping
NHR Core Contributions Attack Surface
REST API Routes 2
WordPress Hooks 8
Maintenance & Trust
NHR Core Contributions Maintenance & Trust
Maintenance Signals
Community Trust
NHR Core Contributions Alternatives
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin
ultimate-member
Membership & community plugin with user profiles, registration & login, member directories, content restriction, user roles and much more.
Ultimate Member – reCAPTCHA
um-recaptcha
Stop bots on your registration & login forms with Google reCAPTCHA
WP User Manager – User Profile Builder & Membership
wp-user-manager
The most customizable profiles & community builder WordPress plugin with front-end login, registration, profile customization and content restriction.
ProfileGrid – User Profiles, Groups and Communities
profilegrid-user-profiles-groups-and-communities
Custom user profiles plugin ❤ with paid memberships, groups, communities, content restriction, user registration, messaging, WooCommerce memberships, …
Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress
youzify
The best BuddyPress plugin for building online communities, user profile, social networks, and membership sites on WordPress with tons of features.
NHR Core Contributions Developer Profile
4 plugins · 180 total installs
How We Detect NHR Core Contributions
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/nhrrob-core-contributions/assets/js/frontend.js/wp-content/plugins/nhrrob-core-contributions/assets/js/admin.js/wp-content/plugins/nhrrob-core-contributions/assets/dashboard/build/index.js/wp-content/plugins/nhrrob-core-contributions/assets/js/common.js/wp-content/plugins/nhrrob-core-contributions/assets/css/frontend.css/wp-content/plugins/nhrrob-core-contributions/assets/css/admin.out.css/wp-content/plugins/nhrrob-core-contributions/assets/dashboard/build/style-index.cssnhrcc-scriptnhrcc-admin-scriptnhrcc-admin-settings-scriptnhrcc-common-scriptnhrcc-scriptnhrcc-admin-scriptnhrcc-admin-settings-scriptnhrcc-common-scriptnhrcc-stylenhrcc-admin-stylenhrcc-admin-settings-styleHTML / DOM Fingerprints
nhrcc-dashboarddata-nhrcc-tabnhrcc_obj