
DSGVO All in one for WP Security & Risk Analysis
wordpress.org/plugins/dsgvo-all-in-one-for-wpAn All in One GDPR Plugin for everything! Responsive Cookie Notice - Imprint & Privacy Policy Generator - integrate external Services GDPR complia …
Is DSGVO All in one for WP Safe to Use in 2026?
Generally Safe
Score 97/100DSGVO All in one for WP has a strong security track record. Known vulnerabilities have been patched promptly.
The dsgvo-all-in-one-for-wp plugin version 4.9 presents a mixed security posture. While the plugin demonstrates strong practices in output escaping, with 99% of outputs properly handled, and no critical or high-severity taint flows detected, there are significant areas of concern. A substantial attack surface is exposed through 19 AJAX handlers that lack authentication checks, making them potential entry points for unauthorized actions. The presence of the `unserialize` function, a known risk for deserialization vulnerabilities, is also a notable point of caution.
The plugin's vulnerability history, with 5 previously disclosed medium-severity CVEs primarily involving Cross-Site Request Forgery and Cross-Site Scripting, suggests a recurring pattern of vulnerabilities that, while not critical, can still impact users. The fact that none are currently unpatched is positive, but the history indicates a need for vigilant maintenance. The static analysis reveals that 14% of SQL queries do not use prepared statements, which could be a vector for SQL injection if not handled carefully elsewhere. Overall, the plugin has a good foundation in output sanitization but requires significant attention to securing its AJAX endpoints and addressing its past vulnerability trends.
Key Concerns
- 19 unprotected AJAX handlers
- 14% SQL queries not using prepared statements
- 1 dangerous function detected (unserialize)
- 5 medium severity CVEs in history
- 1 unsanitized path in taint analysis
DSGVO All in one for WP Security Vulnerabilities
CVEs by Year
Severity Breakdown
5 total CVEs
DSGVO All in one for WP <= 4.6 - Cross-Site Request Forgery to Account Deletion
DSGVO All in one for WP <= 4.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
DSGVO All in one for WP <= 4.3 - Cross-Site Request Forgery
DSGVO All in one for WP <= 4.2 - Authenticated (Administrator+) Stored Cross-Site Scripting
DSGVO All in one for WP <= 3.9 - Unauthenticated Stored Cross-Site Scripting
DSGVO All in one for WP Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
DSGVO All in one for WP Attack Surface
AJAX Handlers 19
Shortcodes 14
WordPress Hooks 39
Maintenance & Trust
DSGVO All in one for WP Maintenance & Trust
Maintenance Signals
Community Trust
DSGVO All in one for WP Alternatives
CookieHub – Cookie Consent Banner (DSGVO, CCPA, RGPD and GDPR compliance)
cookiehub
Take control effortlessly with CookieHub – GDPR-compliant solution for cookie management and compliance.
Conzent – Cookie Banner – Conzent CMP – Google CMP & IAB TCF Certified
conzent
Easily set up cookie banner or cookie notice and cookie policy page for GDPR (DSGVO, RGPD) compliance. Also supports CCPA/CPRA and other major global …
Privacy Offload – GDPR/CCPA Manager
gdpr-ccpa-compliance
Configure your Cookie Notice, Cookie Consent and Cookie Policy with our Wizard and Cookie Scan. Supports GDPR, DSGVO, CCPA and PIPEDA.
CodingFreaks Cookie-Manager
codingfreaks-cookiemanager
Cookie Management made easy, use our Cookie Consent Manager Plugin to comply with the EU Cookie Law, and enjoy easy configuration.
Complianz – GDPR/CCPA Cookie Consent
complianz-gdpr
Configure your Cookie Banner, Cookie Consent and Cookie Policy with our Wizard and Cookies Scan.
DSGVO All in one for WP Developer Profile
7 plugins · 21K total installs
How We Detect DSGVO All in one for WP
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/dsgvo-all-in-one-for-wp/core/js/dsgvo_admin_scripts.js/wp-content/plugins/dsgvo-all-in-one-for-wp/core/css/dsgvo_admin_styles.css/wp-content/plugins/dsgvo-all-in-one-for-wp/core/inc/exporter_fetch_datas.php/wp-content/plugins/dsgvo-all-in-one-for-wp/core/inc/texts.php/wp-content/plugins/dsgvo-all-in-one-for-wp/core/inc/blocks.php/wp-content/plugins/dsgvo-all-in-one-for-wp/core/js/dsgvo_admin_scripts.jsdsgvo-all-in-one-for-wp/core/js/dsgvo_admin_scripts.js?ver=dsgvo-all-in-one-for-wp/core/css/dsgvo_admin_styles.css?ver=HTML / DOM Fingerprints
dsgvoaio-settings-page<!-- DSGVO All in one for WP --><!-- START DSGVO-ALL-IN-ONE-FOR-WP FREE --><!-- END DSGVO-ALL-IN-ONE-FOR-WP FREE -->data-dsgvoaio-noncedsgvo_ajax_objectdsgvoaio_vue_data