
Rhino Support for WordPress Security & Risk Analysis
wordpress.org/plugins/rhino-supportEasily connect a WordPress site to your help desk, powered by RhinoSupport.com. Instantly embed support ticket forms with a simple shortcode.
Is Rhino Support for WordPress Safe to Use in 2026?
Generally Safe
Score 100/100Rhino Support for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "rhino-support" plugin version 1.0.62 demonstrates a mixed security posture. On the positive side, it has no known historical vulnerabilities and utilizes prepared statements for all its SQL queries. Furthermore, all entry points appear to have some form of authentication or capability check, which is a strong preventative measure against unauthorized access.
However, significant concerns arise from the static analysis. A striking 9 out of 9 analyzed taint flows involve unsanitized paths, indicating a high potential for path traversal or directory manipulation vulnerabilities. Compounding this, a very low rate of proper output escaping (4%) suggests a high risk of cross-site scripting (XSS) vulnerabilities across its 52 output points. The presence of a bundled, potentially outdated library (Select2 v3.3.1) also introduces a risk if this library has known security flaws not reflected in the plugin's CVE history.
While the absence of recorded CVEs is encouraging, the numerous unsanitized paths and the severely inadequate output escaping are critical red flags that cannot be ignored. The plugin has strengths in its SQL handling and entry point protection, but the identified code-level weaknesses present a substantial security risk that needs immediate attention.
Key Concerns
- High number of unsanitized path taint flows
- Very low rate of output escaping
- Bundled outdated library (Select2 v3.3.1)
Rhino Support for WordPress Security Vulnerabilities
Rhino Support for WordPress Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Rhino Support for WordPress Attack Surface
Shortcodes 2
WordPress Hooks 24
Maintenance & Trust
Rhino Support for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
Rhino Support for WordPress Alternatives
Live Chat with Messenger Customer Chat
fb-messenger-live-chat
Support your customers via Facebook Messenger Live Chat conveniently from your own website.
Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin
majestic-support
Majestic Support for WordPress is a top-tier ticket system that can significantly enhance your customers' support experience.
Zendesk Support for WordPress
zendesk
Bring the helpdesk into your blog
Re:amaze Helpdesk & Live Chat
reamaze
Boost sales conversions, loyalty, and engagement. Manage your social, email, sms, live chat, FAQ for your WordPress or WooCommerce store.
ChipBot – Video, Live Chat, & AI Help Desk
chipbot
ChipBot turns your website into a face-to-face story experience powered by AI, video, and chat.
Rhino Support for WordPress Developer Profile
1 plugin · 10 total installs
How We Detect Rhino Support for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/rhino-support/images/wprhino.png/wp-content/plugins/rhino-support/css/rhino_style.css/wp-content/plugins/rhino-support/js/select2.min.js/wp-content/plugins/rhino-support/css/select2.css/wp-content/plugins/rhino-support/js/deptselect.js/wp-content/plugins/rhino-support/css/rhino_responsive_style.css/wp-content/plugins/rhino-support/js/rhino_responsive_scripts.jsrhino-support/css/rhino_style.css?ver=rhino-support/js/select2.min.js?ver=rhino-support/css/select2.css?ver=rhino-support/js/deptselect.js?ver=rhino-support/css/rhino_responsive_style.css?ver=rhino-support/js/rhino_responsive_scripts.js?ver=HTML / DOM Fingerprints
rhinopopoverRhinolistdivrhinosuccessdata-htmldata-toggledata-contentRhinoTinyMCEPluginWP_Rhino_Supportrhino_settings_groupwprhinosupport_keywprhinosupport_remote_authwprhinosupport_version+15 more<link rel="stylesheet" type="text/css" href="http://cdn.datatables.net/plug-ins/be7019ee387/integration/bootstrap/3/dataTables.bootstrap.css"><table id="example" class="table table-striped table-bordered" cellspacing="0" width="100%"><th>Subject</th><th>Created</th>