CardanoPress – Cardano Blockchain Integration for WordPress Security & Risk Analysis

wordpress.org/plugins/cardanopress

Integrate the Cardano blockchain with your WordPress website. Merging Web2 and Web3.

40 active installs v1.33.0 PHP 7.4+ WP 5.9+ Updated Feb 2, 2026
adablockchaincardanotoken-gatingweb3
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is CardanoPress – Cardano Blockchain Integration for WordPress Safe to Use in 2026?

Generally Safe

Score 100/100

CardanoPress – Cardano Blockchain Integration for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The plugin 'cardanopress' v1.33.0 exhibits a generally strong security posture with no recorded historical vulnerabilities and a high percentage of properly escaped outputs and prepared SQL statements. The absence of dangerous functions, file operations, and external HTTP requests also contributes positively. However, a significant concern arises from the substantial attack surface presented by its AJAX handlers. A notable 11 out of 13 AJAX handlers lack authentication checks, exposing them to potential unauthorized execution. While no critical or high severity taint flows were identified, the two identified flows with unsanitized paths warrant attention, even if their impact is currently assessed as low. The plugin's adherence to capability checks and nonce checks in most cases demonstrates a commitment to WordPress security best practices, but the unauthenticated AJAX endpoints represent a clear risk that could be exploited by attackers to perform actions on behalf of users or to gain unauthorized access to data if these handlers perform sensitive operations.

Despite the positive aspects like the lack of CVEs and good data handling practices, the significant number of unprotected AJAX endpoints is a weakness that could be leveraged. The vulnerability history being clean is a good indicator, but the current static analysis findings highlight areas for immediate improvement. A balanced conclusion is that while the plugin has a solid foundation in secure coding, the unauthenticated AJAX handlers introduce a material risk that needs to be addressed to further strengthen its security profile.

Key Concerns

  • Unprotected AJAX handlers
  • Flows with unsanitized paths
Vulnerabilities
None known

CardanoPress – Cardano Blockchain Integration for WordPress Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

CardanoPress – Cardano Blockchain Integration for WordPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
11
196 escaped
Nonce Checks
8
Capability Checks
13
File Operations
0
External Requests
2
Bundled Libraries
1

Bundled Libraries

Guzzle

Output Escaping

95% escaped207 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
theme (src\Compatibility.php:57)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
11 unprotected

CardanoPress – Cardano Blockchain Integration for WordPress Attack Surface

Entry Points23
Unprotected11

AJAX Handlers 13

authwp_ajax_cardanopress_save_handlesrc\Actions\CoreAction.php:32
noprivwp_ajax_cardanopress_user_accountsrc\Actions\WalletAction.php:31
authwp_ajax_cardanopress_user_accountsrc\Actions\WalletAction.php:32
authwp_ajax_cardanopress_reconnect_accountsrc\Actions\WalletAction.php:33
authwp_ajax_cardanopress_sync_assetssrc\Actions\WalletAction.php:34
authwp_ajax_cardanopress_user_changesrc\Actions\WalletAction.php:35
authwp_ajax_cardanopress_protocol_parameterssrc\Actions\WalletAction.php:36
authwp_ajax_cardanopress_account_detailssrc\Actions\WalletAction.php:37
authwp_ajax_cardanopress_delegation_datasrc\Actions\WalletAction.php:38
authwp_ajax_cardanopress_wallet_transactionsrc\Actions\WalletAction.php:39
noprivwp_ajax_cardanopress_payment_addresssrc\Actions\WalletAction.php:40
authwp_ajax_cardanopress_payment_addresssrc\Actions\WalletAction.php:41
authwp_ajax_cardanopress_compatibility_checksrc\Installer.php:42

Shortcodes 10

[cardanopress_option] src\Shortcode.php:32
[cardanopress_template] src\Shortcode.php:33
[cardanopress_template_if] src\Shortcode.php:34
[cardanopress_userprofile] src\Shortcode.php:35
[cardanopress_delegationpool] src\Shortcode.php:36
[cardanopress_wallet_balance] src\Shortcode.php:37
[cardanopress_component_cardanopress] src\Shortcode.php:38
[cardanopress_component_pooldelegation] src\Shortcode.php:39
[cardanopress_component_paymentform] src\Shortcode.php:40
[cardanopress_component_splitform] src\Shortcode.php:41
WordPress Hooks 42
actioninitclass-tgm-plugin-activation.php:269
filterload_textdomain_mofileclass-tgm-plugin-activation.php:270
actioninitclass-tgm-plugin-activation.php:273
actionadmin_menuclass-tgm-plugin-activation.php:422
actionadmin_headclass-tgm-plugin-activation.php:423
filterinstall_plugin_complete_actionsclass-tgm-plugin-activation.php:426
filterupdate_plugin_complete_actionsclass-tgm-plugin-activation.php:427
actionadmin_noticesclass-tgm-plugin-activation.php:430
actionadmin_initclass-tgm-plugin-activation.php:431
actionadmin_enqueue_scriptsclass-tgm-plugin-activation.php:432
actionload-plugins.phpclass-tgm-plugin-activation.php:437
actionswitch_themeclass-tgm-plugin-activation.php:440
actionswitch_themeclass-tgm-plugin-activation.php:443
actionadmin_initclass-tgm-plugin-activation.php:448
actionswitch_themeclass-tgm-plugin-activation.php:453
actionload_textdomain_mofileclass-tgm-plugin-activation.php:476
filterupgrader_source_selectionclass-tgm-plugin-activation.php:890
actionplugins_loadedclass-tgm-plugin-activation.php:2113
filtertgmpa_table_data_itemsclass-tgm-plugin-activation.php:2237
filterupgrader_source_selectionclass-tgm-plugin-activation.php:2978
actionadmin_initclass-tgm-plugin-activation.php:3148
actionupgrader_process_completeclass-tgm-plugin-activation.php:3243
filterupgrader_post_installclass-tgm-plugin-activation.php:3302
filterupgrader_post_installclass-tgm-plugin-activation.php:3447
actionwp_loginsrc\Actions\CoreAction.php:30
actionparse_requestsrc\Actions\CoreAction.php:31
actionwp_enqueue_scriptssrc\Actions\CoreAction.php:33
actiontgmpa_registersrc\Admin.php:41
actioninitsrc\Admin.php:42
actioncardanopress_loadedsrc\Application.php:43
actionplugins_loadedsrc\Installer.php:37
actionadmin_noticessrc\Installer.php:38
actionadmin_noticessrc\Installer.php:39
actionadmin_noticessrc\Installer.php:40
actionadmin_noticessrc\Installer.php:41
actionafter_switch_themesrc\Installer.php:43
actioninitsrc\Installer.php:44
actionwp_enqueue_scriptssrc\Manifest.php:23
actionwp_body_opensrc\Manifest.php:24
actionwp_footersrc\Manifest.php:25
actionwp_footersrc\Manifest.php:128
filtertheme_page_templatessrc\Templates.php:31
Maintenance & Trust

CardanoPress – Cardano Blockchain Integration for WordPress Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.99
Last updatedFeb 2, 2026
PHP min version7.4
Downloads9K

Community Trust

Rating100/100
Number of ratings14
Active installs40
Developer Profile

CardanoPress – Cardano Blockchain Integration for WordPress Developer Profile

cardanopress

3 plugins · 60 total installs

91
trust score
Avg Security Score
95/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect CardanoPress – Cardano Blockchain Integration for WordPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cardanopress/dist/cardanopress.css/wp-content/plugins/cardanopress/dist/cardanopress.js
Script Paths
/wp-content/plugins/cardanopress/dependencies/vendor/pbwebdev/cardanopress/src/Application.php/wp-content/plugins/cardanopress/dependencies/vendor/pbwebdev/cardanopress/src/Installer.php/wp-content/plugins/cardanopress/dependencies/vendor/autoload_packages.php

HTML / DOM Fingerprints

CSS Classes
cardanopress
HTML Comments
<!-- CardanoPress Core --><!-- CardanoPress: Shortcode -->
Data Attributes
data-cardanopress-buttondata-cardanopress-linkdata-cardanopress-dialog
JS Globals
cardanoPressApiCardanoPress
Shortcode Output
[cardanopress_wallet_auth][cardanopress_asset_gallery][cardanopress_stake_pool_details]
FAQ

Frequently Asked Questions about CardanoPress – Cardano Blockchain Integration for WordPress