Was This Helpful? – Article Feedback Security & Risk Analysis

wordpress.org/plugins/riaco-was-this-helpful

Was this helpful? plugin for WordPress adds a thumbs up/down box to collect quick article feedback on posts and pages.

20 active installs v2.1.2 PHP 7.4+ WP 6.2+ Updated Oct 9, 2025
article-feedbackfeedbackhelpfulwas-this-helpfulwordpress-feedback-plugin
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Was This Helpful? – Article Feedback Safe to Use in 2026?

Generally Safe

Score 100/100

Was This Helpful? – Article Feedback has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7mo ago
Risk Assessment

The 'riaco-was-this-helpful' plugin v2.1.2 demonstrates a generally strong security posture based on the provided static analysis. The complete absence of critical or high-severity taint flows, along with 100% of SQL queries using prepared statements, are significant strengths. Furthermore, the plugin incorporates a good number of nonce and capability checks, indicating an awareness of common WordPress security practices for its entry points. The lack of file operations and external HTTP requests further reduces the potential attack surface.

However, a minor concern arises from the 95% output escaping rate. While high, the 5% of unescaped outputs, though not explicitly flagged as critical in the taint analysis, could potentially lead to cross-site scripting (XSS) vulnerabilities if the unsafely handled data is user-controllable. The vulnerability history being entirely clear is a positive indicator, suggesting the developers are either diligent in addressing issues or the plugin hasn't been a significant target for vulnerability discovery. Overall, the plugin appears to be well-secured, with only minor potential for improvement in output sanitization to achieve a perfect score.

Key Concerns

  • Unescaped output detected
Vulnerabilities
None known

Was This Helpful? – Article Feedback Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Was This Helpful? – Article Feedback Release Timeline

v2.1.2Current
v2.1.1
v2.1.0
v2.0.5
v2.0.4
v2.0.3
v2.0.2
v2.0.1
Code Analysis
Analyzed Mar 16, 2026

Was This Helpful? – Article Feedback Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
14 prepared
Unescaped Output
7
122 escaped
Nonce Checks
6
Capability Checks
8
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared14 total queries

Output Escaping

95% escaped129 total outputs
Attack Surface

Was This Helpful? – Article Feedback Attack Surface

Entry Points4
Unprotected0

AJAX Handlers 3

authwp_ajax_riwth_review_actionincludes\class-admin-review-notice.php:68
authwp_ajax_riwth_save_feedbackincludes\class-ajax.php:20
noprivwp_ajax_riwth_save_feedbackincludes\class-ajax.php:21

Shortcodes 1

[riwth_helpful_box] includes\class-shortcode.php:8
WordPress Hooks 30
actionadmin_bar_menuincludes\class-admin-bar.php:11
actionadmin_initincludes\class-admin-columns.php:29
actionpre_get_postsincludes\class-admin-columns.php:45
filterposts_joinincludes\class-admin-columns.php:120
filterposts_fieldsincludes\class-admin-columns.php:121
filterposts_orderbyincludes\class-admin-columns.php:122
filterposts_groupbyincludes\class-admin-columns.php:123
actionin_admin_footerincludes\class-admin-pages-footer.php:22
filteradmin_footer_textincludes\class-admin-pages-footer.php:23
actionadmin_noticesincludes\class-admin-review-notice.php:66
actionadmin_enqueue_scriptsincludes\class-admin-review-notice.php:67
actioninitincludes\class-block.php:22
actionenqueue_block_assetsincludes\class-block.php:23
actionenqueue_block_editor_assetsincludes\class-block.php:24
filterthe_contentincludes\class-box.php:8
actionadd_meta_boxesincludes\class-metabox-stats.php:7
actionadd_meta_boxesincludes\class-metabox.php:7
actionsave_postincludes\class-metabox.php:8
actionriwth_after_metabox_statsincludes\class-reset-stats.php:22
filterpost_row_actionsincludes\class-reset-stats.php:24
filterpage_row_actionsincludes\class-reset-stats.php:25
actionadmin_action_riwth_reset_statsincludes\class-reset-stats.php:27
actionadmin_noticesincludes\class-reset-stats.php:28
actionadmin_menuincludes\class-settings.php:8
actionadmin_menuincludes\class-settings.php:9
actionadmin_initincludes\class-settings.php:10
actionadmin_enqueue_scriptsincludes\class-settings.php:11
actionwp_enqueue_scriptsincludes\class-was-this-helpful.php:105
actionadmin_enqueue_scriptsincludes\class-was-this-helpful.php:106
actionplugins_loadedincludes\class-was-this-helpful.php:107
Maintenance & Trust

Was This Helpful? – Article Feedback Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedOct 9, 2025
PHP min version7.4
Downloads895

Community Trust

Rating100/100
Number of ratings1
Active installs20
Developer Profile

Was This Helpful? – Article Feedback Developer Profile

robertoiacono

12 plugins · 100 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Was This Helpful? – Article Feedback

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/riaco-was-this-helpful/assets/public/css/style.css/wp-content/plugins/riaco-was-this-helpful/assets/public/js/script.js/wp-content/plugins/riaco-was-this-helpful/assets/admin/js/riwth-review-notice.js
Script Paths
/wp-content/plugins/riaco-was-this-helpful/assets/public/js/script.js/wp-content/plugins/riaco-was-this-helpful/assets/admin/js/riwth-review-notice.js
Version Parameters
riaco-was-this-helpful/assets/public/css/style.css?ver=riaco-was-this-helpful/assets/public/js/script.js?ver=riaco-was-this-helpful/assets/admin/js/riwth-review-notice.js?ver=

HTML / DOM Fingerprints

CSS Classes
riwth-feedback-boxriwth-feedback-contentriwth-feedback-yesriwth-feedback-noriwth-feedback-thank-youriwth-review-notice
Data Attributes
data-feedback-iddata-noncedata-actiondata-id
JS Globals
RIWTH_AJAXRIWTH_Review
Shortcode Output
[riwth_feedback][riwth_admin_review]
FAQ

Frequently Asked Questions about Was This Helpful? – Article Feedback