Consensu.io | Conformidade e Consentimento de Cookies para LGPD Security & Risk Analysis

wordpress.org/plugins/consensu-io

Configure facilmente consentimento e monitoramento de cookies em seu website e esteja em conformidade com a LGPD.

300 active installs v1.0.5 PHP 5.6+ WP 4.1.0+ Updated Nov 4, 2024
complianceconsentimento-de-cookiesgdprlgpdprivacy
92
A · Safe
CVEs total1
Unpatched0
Last CVENov 23, 2023
Download
Safety Verdict

Is Consensu.io | Conformidade e Consentimento de Cookies para LGPD Safe to Use in 2026?

Generally Safe

Score 92/100

Consensu.io | Conformidade e Consentimento de Cookies para LGPD has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Nov 23, 2023Updated 1yr ago
Risk Assessment

The consensu-io plugin v1.0.5 exhibits a generally strong security posture based on the static analysis. The absence of dangerous functions, proper escaping of all outputs, and the use of prepared statements for all SQL queries are excellent security practices. Furthermore, the presence of nonce and capability checks on several functions indicates a thoughtful approach to protecting against common WordPress vulnerabilities. The plugin also appears to have a clean slate regarding critical or high-severity issues in its vulnerability history, with only one medium-severity vulnerability noted in the past.

However, a key area of concern is the complete lack of identified entry points (AJAX handlers, REST API routes, shortcodes, cron events) in the static analysis. While this might suggest a very limited feature set or an unconventional implementation, it also makes it difficult to fully assess the attack surface. The single medium vulnerability in its history, categorized as 'Missing Authorization,' is a notable flag, even though it is currently patched. This suggests that while the developers are addressing vulnerabilities, there's a history of authorization issues that warrants continued vigilance. The plugin's strengths lie in its code hygiene and proactive checks, but the potential for undiscovered entry points and the past authorization issues necessitate a cautious approach.

Overall, the plugin demonstrates good coding practices, but the limited visibility into its attack surface and the past vulnerability type are areas that merit attention. The lack of any identified entry points in the static analysis is unusual and could indicate either a very limited plugin or a potential gap in the analysis itself. The presence of a past medium-severity 'Missing Authorization' vulnerability, even if patched, is a recurring theme for WordPress plugins and should be monitored.

Key Concerns

  • Past medium severity vulnerability (Missing Authorization)
Vulnerabilities
1

Consensu.io | Conformidade e Consentimento de Cookies para LGPD Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2023-48280medium · 5.3Missing Authorization

Consensu.io <= 1.0.3 - Missing Authorization via update_config_db()

Nov 23, 2023 Patched in 1.0.4 (351d)
Code Analysis
Analyzed Mar 16, 2026

Consensu.io | Conformidade e Consentimento de Cookies para LGPD Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
6 escaped
Nonce Checks
1
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped6 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
handle_form_submission (admin\class-consensu-io-admin.php:67)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Consensu.io | Conformidade e Consentimento de Cookies para LGPD Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actionadmin_menuadmin\class-consensu-io-admin.php:59
actionadmin_initadmin\class-consensu-io-admin.php:60
actionadmin_noticesadmin\class-consensu-io-admin.php:61
actionadmin_noticesadmin\class-consensu-io-admin.php:85
actionplugins_loadedconsensu-io.php:80
actionplugins_loadedincludes\class-consensu-io.php:143
actionadmin_enqueue_scriptsincludes\class-consensu-io.php:161
actionadmin_enqueue_scriptsincludes\class-consensu-io.php:162
actionwp_footerincludes\class-consensu-io.php:177
filterscript_loader_tagincludes\class-consensu-io.php:179
Maintenance & Trust

Consensu.io | Conformidade e Consentimento de Cookies para LGPD Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedNov 4, 2024
PHP min version5.6
Downloads11K

Community Trust

Rating86/100
Number of ratings3
Active installs300
Developer Profile

Consensu.io | Conformidade e Consentimento de Cookies para LGPD Developer Profile

Consensu.io

1 plugin · 300 total installs

73
trust score
Avg Security Score
92/100
Avg Patch Time
351 days
View full developer profile
Detection Fingerprints

How We Detect Consensu.io | Conformidade e Consentimento de Cookies para LGPD

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/consensu-io/admin/css/consensu-io-admin.css/wp-content/plugins/consensu-io/admin/js/consensu-io-admin.js
Script Paths
/wp-content/plugins/consensu-io/admin/js/consensu-io-admin.js
Version Parameters
consensu-io-admin.css?ver=consensu-io-admin.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-consensu-io-client-keydata-consensu-io-debug-mode
JS Globals
window.consensu_io_client_keywindow.consensu_io_debug_mode
FAQ

Frequently Asked Questions about Consensu.io | Conformidade e Consentimento de Cookies para LGPD