CardanoPress – Governance for Cardano Security & Risk Analysis

wordpress.org/plugins/cardanopress-governance

Allows users to be able to submit, participate and vote on governance proposals. Voting is done on-chain by submitting transactions with metadata.

10 active installs v1.10.0 PHP 7.4+ WP 5.9+ Updated Dec 5, 2025
adablockchaincardanotoken-gatingweb3
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is CardanoPress – Governance for Cardano Safe to Use in 2026?

Generally Safe

Score 100/100

CardanoPress – Governance for Cardano has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The "cardanopress-governance" plugin, version 1.10.0, exhibits a generally strong security posture based on the provided static analysis. The plugin demonstrates good practices by implementing nonce and capability checks on its entry points, and importantly, all identified SQL queries utilize prepared statements, eliminating the risk of SQL injection through this vector. The limited attack surface, with only three identified entry points and no unauthenticated ones, further contributes to its robust security. Furthermore, the near-perfect output escaping suggests a low risk of cross-site scripting (XSS) vulnerabilities stemming from improper data handling.

The absence of any recorded CVEs, critical taint flows, or concerning code signals like dangerous functions or file operations is highly positive. This indicates a well-maintained and secure codebase with no known historical vulnerabilities. The use of the Guzzle library, while a dependency, is noted, but without information on its version or known vulnerabilities, it poses a neutral risk in this assessment.

In conclusion, "cardanopress-governance" v1.10.0 appears to be a secure plugin with a commendable focus on input validation and output sanitization. The lack of historical vulnerabilities further reinforces this assessment. The only minor consideration is the bundled Guzzle library, which would warrant a deeper dive if its version were known to be outdated or to have known exploits.

Vulnerabilities
None known

CardanoPress – Governance for Cardano Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

CardanoPress – Governance for Cardano Release Timeline

v1.10.0Current
v1.9.0
v1.8.0
v1.7.0
v1.6.0
v1.5.0
v1.4.0
v1.3.0
v1.2.1
v1.2.0
v1.1.0
v1.0.0
Code Analysis
Analyzed Apr 16, 2026

CardanoPress – Governance for Cardano Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
4 prepared
Unescaped Output
7
214 escaped
Nonce Checks
7
Capability Checks
13
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Guzzle

SQL Query Safety

100% prepared4 total queries

Output Escaping

97% escaped221 total outputs
Attack Surface

CardanoPress – Governance for Cardano Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 2

authwp_ajax_cp-governance_proposal_vote_verifysrc/Actions.php:16
authwp_ajax_cp-governance_proposal_vote_completesrc/Actions.php:17

Shortcodes 1

[cp-governance_power] src/Shortcode.php:23
WordPress Hooks 43
actioninitclass-tgm-plugin-activation.php:269
filterload_textdomain_mofileclass-tgm-plugin-activation.php:270
actioninitclass-tgm-plugin-activation.php:273
actionadmin_menuclass-tgm-plugin-activation.php:422
actionadmin_headclass-tgm-plugin-activation.php:423
filterinstall_plugin_complete_actionsclass-tgm-plugin-activation.php:426
filterupdate_plugin_complete_actionsclass-tgm-plugin-activation.php:427
actionadmin_noticesclass-tgm-plugin-activation.php:430
actionadmin_initclass-tgm-plugin-activation.php:431
actionadmin_enqueue_scriptsclass-tgm-plugin-activation.php:432
actionload-plugins.phpclass-tgm-plugin-activation.php:437
actionswitch_themeclass-tgm-plugin-activation.php:440
actionswitch_themeclass-tgm-plugin-activation.php:443
actionadmin_initclass-tgm-plugin-activation.php:448
actionswitch_themeclass-tgm-plugin-activation.php:453
actionload_textdomain_mofileclass-tgm-plugin-activation.php:476
filterupgrader_source_selectionclass-tgm-plugin-activation.php:890
actionplugins_loadedclass-tgm-plugin-activation.php:2113
filtertgmpa_table_data_itemsclass-tgm-plugin-activation.php:2237
filterupgrader_source_selectionclass-tgm-plugin-activation.php:2978
actionadmin_initclass-tgm-plugin-activation.php:3148
actionupgrader_process_completeclass-tgm-plugin-activation.php:3243
filterupgrader_post_installclass-tgm-plugin-activation.php:3302
filterupgrader_post_installclass-tgm-plugin-activation.php:3447
actioninitdependencies/ThemePlate/CPT/Base.php:165
filteruse_block_editor_for_post_typedependencies/ThemePlate/CPT/PostType.php:162
filterpost_updated_messagesdependencies/ThemePlate/CPT/PostType.php:164
filterbulk_post_updated_messagesdependencies/ThemePlate/CPT/PostType.php:166
filterterm_updated_messagesdependencies/ThemePlate/CPT/Taxonomy.php:110
actionwp_enqueue_scriptssrc/Actions.php:18
actiontgmpa_registersrc/Admin.php:38
actioninitsrc/Admin.php:39
actioncardanopress_loadedsrc/Application.php:40
actionadmin_noticessrc/Installer.php:28
actionadmin_noticessrc/Installer.php:29
actionadmin_noticessrc/Installer.php:30
actionadmin_noticessrc/Installer.php:31
actionwp_enqueue_scriptssrc/Manifest.php:23
actionwp_insert_postsrc/ProposalCPT.php:36
actionwp_insert_postsrc/ProposalCPT.php:37
actionpre_get_postssrc/ProposalCPT.php:38
filteruse_block_editor_for_post_typesrc/ProposalCPT.php:39
actioninitsrc/ProposalFields.php:25
Maintenance & Trust

CardanoPress – Governance for Cardano Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.99
Last updatedDec 5, 2025
PHP min version7.4
Downloads7K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

CardanoPress – Governance for Cardano Developer Profile

cardanopress

5 plugins · 80 total installs

90
trust score
Avg Security Score
94/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect CardanoPress – Governance for Cardano

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cardanopress-governance/assets/css/governance.css/wp-content/plugins/cardanopress-governance/assets/js/governance.js/wp-content/plugins/cardanopress-governance/assets/js/settings.js
Script Paths
/wp-content/plugins/cardanopress-governance/assets/js/governance.js/wp-content/plugins/cardanopress-governance/assets/js/settings.js
Version Parameters
cardanopress-governance/assets/css/governance.css?ver=cardanopress-governance/assets/js/governance.js?ver=cardanopress-governance/assets/js/settings.js?ver=

HTML / DOM Fingerprints

CSS Classes
cp-governance-settings-formcp-governance-settings-field
HTML Comments
<!-- Accessed directly --><!-- Load the main plugin class --><!-- Instantiate -->
Data Attributes
data-cp-governance-setting
JS Globals
cpGovernance
FAQ

Frequently Asked Questions about CardanoPress – Governance for Cardano