Rhino Support for WordPress Security & Risk Analysis

wordpress.org/plugins/rhino-support

Easily connect a WordPress site to your help desk, powered by RhinoSupport.com. Instantly embed support ticket forms with a simple shortcode.

10 active installs v1.0.62 PHP + WP 3.3+ Updated Unknown
customer-supporthelp-deskhelp-desk-softwarerhino-supportsupport-desk
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Rhino Support for WordPress Safe to Use in 2026?

Generally Safe

Score 100/100

Rhino Support for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "rhino-support" plugin version 1.0.62 demonstrates a mixed security posture. On the positive side, it has no known historical vulnerabilities and utilizes prepared statements for all its SQL queries. Furthermore, all entry points appear to have some form of authentication or capability check, which is a strong preventative measure against unauthorized access.

However, significant concerns arise from the static analysis. A striking 9 out of 9 analyzed taint flows involve unsanitized paths, indicating a high potential for path traversal or directory manipulation vulnerabilities. Compounding this, a very low rate of proper output escaping (4%) suggests a high risk of cross-site scripting (XSS) vulnerabilities across its 52 output points. The presence of a bundled, potentially outdated library (Select2 v3.3.1) also introduces a risk if this library has known security flaws not reflected in the plugin's CVE history.

While the absence of recorded CVEs is encouraging, the numerous unsanitized paths and the severely inadequate output escaping are critical red flags that cannot be ignored. The plugin has strengths in its SQL handling and entry point protection, but the identified code-level weaknesses present a substantial security risk that needs immediate attention.

Key Concerns

  • High number of unsanitized path taint flows
  • Very low rate of output escaping
  • Bundled outdated library (Select2 v3.3.1)
Vulnerabilities
None known

Rhino Support for WordPress Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Rhino Support for WordPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
50
2 escaped
Nonce Checks
0
Capability Checks
4
File Operations
1
External Requests
4
Bundled Libraries
2

Bundled Libraries

TinyMCESelect23.3.1

Output Escaping

4% escaped52 total outputs
Data Flows
9 unsanitized

Data Flow Analysis

9 flows9 with unsanitized paths
save_api_key (core\class-rhino-pluginmethods.php:270)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Rhino Support for WordPress Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[rhinosupport_create] rhino.php:695
[rhinosupport_listtickets] rhino.php:696
WordPress Hooks 24
actionadmin_initcore\class-rhino-pluginmethods.php:26
actionadmin_noticescore\class-rhino-pluginmethods.php:267
actionadmin_noticescore\class-rhino-pluginmethods.php:276
actionadmin_noticescore\class-rhino-pluginmethods.php:316
actionadmin_noticescore\class-rhino-pluginmethods.php:333
actionadmin_noticescore\class-rhino-pluginmethods.php:352
actionadmin_noticescore\class-rhino-pluginmethods.php:369
actionadmin_noticescore\class-rhino-pluginmethods.php:388
actioninitcore\RhinoTinyMCEPlugin.php:19
filtermce_external_pluginscore\RhinoTinyMCEPlugin.php:33
filtertiny_mce_before_initcore\RhinoTinyMCEPlugin.php:34
actioninitcore\RhinoTinyMCEPlugin.php:281
actioninitcore\RhinoTinyMCEPlugin.php:282
filtermce_external_pluginscore\RhinoTinyMCEPlugin.php:291
filtermce_buttonscore\RhinoTinyMCEPlugin.php:292
filterwp_headrhino.php:699
actionadmin_initrhino.php:702
actionwp_insert_postrhino.php:703
filtercomment_row_actionsrhino.php:706
actionadmin_menurhino.php:710
actionadmin_initrhino.php:713
actioninitrhino.php:714
actioninitrhino.php:715
actionplugins_loadedrhino.php:717
Maintenance & Trust

Rhino Support for WordPress Maintenance & Trust

Maintenance Signals

WordPress version tested3.7.41
Last updatedUnknown
PHP min version
Downloads5K

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

Rhino Support for WordPress Developer Profile

Rhino Support

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Rhino Support for WordPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/rhino-support/images/wprhino.png/wp-content/plugins/rhino-support/css/rhino_style.css/wp-content/plugins/rhino-support/js/select2.min.js/wp-content/plugins/rhino-support/css/select2.css/wp-content/plugins/rhino-support/js/deptselect.js/wp-content/plugins/rhino-support/css/rhino_responsive_style.css/wp-content/plugins/rhino-support/js/rhino_responsive_scripts.js
Version Parameters
rhino-support/css/rhino_style.css?ver=rhino-support/js/select2.min.js?ver=rhino-support/css/select2.css?ver=rhino-support/js/deptselect.js?ver=rhino-support/css/rhino_responsive_style.css?ver=rhino-support/js/rhino_responsive_scripts.js?ver=

HTML / DOM Fingerprints

CSS Classes
rhinopopoverRhinolistdivrhinosuccess
Data Attributes
data-htmldata-toggledata-content
JS Globals
RhinoTinyMCEPluginWP_Rhino_Supportrhino_settings_groupwprhinosupport_keywprhinosupport_remote_authwprhinosupport_version+15 more
Shortcode Output
<link rel="stylesheet" type="text/css" href="http://cdn.datatables.net/plug-ins/be7019ee387/integration/bootstrap/3/dataTables.bootstrap.css"><table id="example" class="table table-striped table-bordered" cellspacing="0" width="100%"><th>Subject</th><th>Created</th>
FAQ

Frequently Asked Questions about Rhino Support for WordPress