Was This Helpful? Security & Risk Analysis

wordpress.org/plugins/was-this-article-helpful

Simple article feedback plugin. find out if the information you provided is helpful to visitors and improve the user experience.

1K active installs v1.0.2 PHP + WP 4.0+ Updated Nov 18, 2024
feedbackhelpfulux
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Was This Helpful? Safe to Use in 2026?

Generally Safe

Score 92/100

Was This Helpful? has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "was-this-article-helpful" plugin version 1.0.2 exhibits a generally good security posture with no recorded vulnerabilities or critical code signals. The static analysis indicates a low attack surface with all identified entry points (AJAX handlers and shortcodes) being protected, albeit with a lack of capability checks on these points. The absence of dangerous functions, SQL injection risks (due to prepared statements), file operations, and external HTTP requests are positive indicators. However, the 50% rate of improperly escaped output is a notable concern, suggesting potential for cross-site scripting (XSS) vulnerabilities if user-supplied data is ever processed and displayed without proper sanitization. The lack of recorded vulnerability history is encouraging, implying a history of secure development, but it does not entirely negate the risks identified in the static analysis, particularly concerning output escaping.

Key Concerns

  • Unescaped output found (50%)
  • No capability checks on entry points
Vulnerabilities
None known

Was This Helpful? Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Was This Helpful? Release Timeline

No version history available.
Code Analysis
Analyzed Mar 16, 2026

Was This Helpful? Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
9
9 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

50% escaped18 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
wthf_options_page (index.php:221)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Was This Helpful? Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 2

authwp_ajax_wthf_ajaxindex.php:141
noprivwp_ajax_wthf_ajaxindex.php:142

Shortcodes 1

[was_this_article_helpful] index.php:355
WordPress Hooks 4
filterthe_contentindex.php:75
actionwp_enqueue_scriptsindex.php:96
actioninitindex.php:207
actionadmin_menuindex.php:216
Maintenance & Trust

Was This Helpful? Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 18, 2024
PHP min version
Downloads13K

Community Trust

Rating94/100
Number of ratings14
Active installs1K
Developer Profile

Was This Helpful? Developer Profile

YellowPencil

3 plugins · 48K total installs

76
trust score
Avg Security Score
95/100
Avg Patch Time
746 days
View full developer profile
Detection Fingerprints

How We Detect Was This Helpful?

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/was-this-article-helpful/css/style.css/wp-content/plugins/was-this-article-helpful/js/script.js
Script Paths
/wp-content/plugins/was-this-article-helpful/js/script.js
Version Parameters
was-this-article-helpful/css/style.css?ver=was-this-article-helpful/js/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
wthf-titlewthf-yes-no
Data Attributes
data-post-iddata-thank-textdata-value
JS Globals
nonce_wthfajaxurl
REST Endpoints
/wp-json/wp/v2/posts
Shortcode Output
[was_this_article_helpful]
FAQ

Frequently Asked Questions about Was This Helpful?