Superb Helper Security & Risk Analysis

wordpress.org/plugins/superb-helper

Superb Helper helps you learn how to use WordPress & build a website with it.

9K active installs v1.3.0 PHP 7.2+ WP 5.1+ Updated Nov 26, 2025
helpersuperb
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Superb Helper Safe to Use in 2026?

Generally Safe

Score 100/100

Superb Helper has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The 'superb-helper' v1.3.0 plugin exhibits a generally strong security posture based on the provided static analysis. It has a limited attack surface with only two AJAX handlers, and crucially, none of these appear to be exposed without authentication checks. The absence of REST API routes, shortcodes, and cron events further minimizes potential entry points. The code also demonstrates good practices with 100% of SQL queries utilizing prepared statements and a high percentage of output being properly escaped. The presence of nonce and capability checks is also encouraging.

There are no identified critical or high-severity issues in the taint analysis, and the plugin has no known historical vulnerabilities (CVEs). This lack of historical issues, combined with the absence of critical code signals like dangerous functions or file operations, suggests a well-developed and maintained plugin. The plugin also doesn't bundle any external libraries, which removes a potential vector for outdated or vulnerable dependencies.

While the overall security is very good, the 12% of unescaped output, though not flagged as critical, represents a minor weakness that could theoretically lead to cross-site scripting (XSS) vulnerabilities if the unescaped data were user-controlled and displayed in a sensitive context. This is the only identifiable area for improvement from the provided data. In conclusion, 'superb-helper' v1.3.0 appears to be a secure plugin with a strong foundation, with only a small area of potential concern regarding output escaping.

Key Concerns

  • Minor unescaped output
Vulnerabilities
None known

Superb Helper Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Superb Helper Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
17
121 escaped
Nonce Checks
9
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

88% escaped138 total outputs
Attack Surface

Superb Helper Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_spbrec_dismiss_noticerecommender\recommender.php:77
authwp_ajax_spbtic_dismiss_noticesrc\notices\class-notices.php:23
WordPress Hooks 7
actionadmin_menuinc\plugin.php:24
actionadmin_enqueue_scriptsinc\plugin.php:25
actionadmin_noticesrecommender\recommender.php:76
actionadmin_initrecommender\recommender.php:78
actionadmin_noticessrc\notices\class-notices.php:22
filterplugin_row_metasuperb-helper.php:63
actioncustomize_registersuperb-helper.php:77
Maintenance & Trust

Superb Helper Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedNov 26, 2025
PHP min version7.2
Downloads336K

Community Trust

Rating0/100
Number of ratings0
Active installs9K
Developer Profile

Superb Helper Developer Profile

Suplugins

6 plugins · 108K total installs

79
trust score
Avg Security Score
100/100
Avg Patch Time
197 days
View full developer profile
Detection Fingerprints

How We Detect Superb Helper

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/superb-helper/assets/css/spb-up.css/wp-content/plugins/superb-helper/assets/css/backend.css/wp-content/plugins/superb-helper/assets/fontawesome/css/fontawesome.css/wp-content/plugins/superb-helper/assets/fontawesome/css/solid.css/wp-content/plugins/superb-helper/assets/lato/styles.css/wp-content/plugins/superb-helper/assets/js/backend.js/wp-content/plugins/superb-helper/assets/js/notices.js
Version Parameters
spb-up.css?ver=backend.css?ver=fontawesome.css?ver=solid.css?ver=styles.css?ver=backend.js?ver=notices.js?ver=

HTML / DOM Fingerprints

CSS Classes
spb-up-stylesheetspb-up.cssspbhlpr-up-stylesheetspbhlpr-stylesheetspbhlpr-fontawesomespbhlpr-fontawesome-sspbhlpr-lato
Data Attributes
spbhlpr_install_pluginsspbhlpr_get_startedspbhlpr_get_started_guidesspbhlpr_user_capabilities
JS Globals
spbhlpr_admin
FAQ

Frequently Asked Questions about Superb Helper