
Dolphy Security & Risk Analysis
wordpress.org/plugins/dolphyDolphy adds a very nice login and registration experience to your Wordpress blog.
Is Dolphy Safe to Use in 2026?
Generally Safe
Score 85/100Dolphy has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "dolphy" v1.3.0 plugin exhibits a generally strong security posture based on the static analysis provided. The absence of identified AJAX handlers, REST API routes, shortcodes, and cron events with unprotected entry points significantly reduces the potential attack surface. The majority of SQL queries utilize prepared statements, and a good percentage of output is properly escaped, indicating a conscientious approach to secure coding practices. The plugin also correctly uses a bundled library (PHPMailer) which is a standard and generally well-maintained component.
However, the presence of two "unserialize" calls is a notable concern. Unserialization of untrusted data is a well-known vector for Remote Code Execution (RCE) vulnerabilities. While the taint analysis found no unsanitized flows, the "unserialize" functions themselves represent a potential risk if user-controlled data is ever passed to them without stringent sanitization or validation beforehand. The complete lack of nonce checks and capability checks across all identified entry points is also a significant weakness, leaving any potential future additions to the attack surface vulnerable to CSRF and unauthorized access if not properly secured.
The plugin's vulnerability history is exceptionally clean, with no recorded CVEs. This suggests a history of responsible development and a lack of previously discovered critical security flaws. However, the absence of past vulnerabilities should not be interpreted as absolute security, especially given the identified "unserialize" functions and the missing authentication/authorization checks. The focus should remain on mitigating the identified code signals of concern.
Key Concerns
- Uses unserialize function
- 0 Nonce checks
- 0 Capability checks
- Output escaping not fully proper (21% not escaped)
- Uses bundled library (PHPMailer)
Dolphy Security Vulnerabilities
Dolphy Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Dolphy Attack Surface
WordPress Hooks 41
Maintenance & Trust
Dolphy Maintenance & Trust
Maintenance Signals
Community Trust
Dolphy Alternatives
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP
userswp
Light weight Front-end login form, User Registration, User Profile and Members Directory plugin.
Pie Register – User Registration, Profiles & Content Restriction
pie-register
Create customized registration forms, Invite through email, Email Notification, User Roles assignment, and more. Pie Register is a User Registration p …
CM Registration – Tailored tool for seamless login and invitation-based registrations
cm-invitation-codes
Manage user registration forms with invitation codes and control access. Simplify login and registration processes using Ajax based solution.
Normalized Forms with Captcha
normalized-forms-with-captcha
Custom Responsive Contact, Login & Register Forms with Captcha. Redirection of Register and Login links to a theme based Register page.
PopForms Lite
popforms-lite
Short Description: Material Design WordPress popup forms with contact, login, signup, and subscribe options.
Dolphy Developer Profile
2 plugins · 0 total installs
How We Detect Dolphy
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/dolphy/assets/images/logo.png/wp-content/plugins/dolphy/assets/images/icon.png/wp-content/plugins/dolphy/assets/images/flutterwave-small.pnghttps://api.ravepay.co/flwv3-pug/getpaidx/api/flwpbf-inline.jsdolphy.php?ver=classes/WooCommerce/Gateways/Flutterwave.php?ver=HTML / DOM Fingerprints
data-paystack-keydata-amountdata-emaildata-refdata-callbackdata-currency+2 moreCYB.Flutterwave.pay/wp-json/dolphy/v1/settings