
Marijuana Age Verify Security & Risk Analysis
wordpress.org/plugins/easy-marijuana-age-verifyAge verification for cannabis, CBD or dispensary websites. Turnkey setup with customization and translation options. Fullscreen, responsive popup.
Is Marijuana Age Verify Safe to Use in 2026?
Generally Safe
Score 100/100Marijuana Age Verify has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "easy-marijuana-age-verify" plugin v2.0.4 presents a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for its SQL queries and not making any external HTTP requests. The absence of known vulnerabilities in its history is also a strong indicator of diligent development and maintenance. Furthermore, the presence of nonce and capability checks on its entry points, while limited, is a positive step towards securing those interactions.
However, significant concerns arise from the attack surface. With two AJAX handlers identified, and crucially, both lacking authentication checks, this plugin exposes two direct points of entry that could be exploited by unauthenticated users. While the taint analysis did not reveal any immediate critical or high-severity issues, the unauthenticated AJAX endpoints represent a potential pathway for attackers to inject malicious data or trigger unintended actions. The relatively low percentage of properly escaped output (48%) also indicates a risk of Cross-Site Scripting (XSS) vulnerabilities, although the severity is difficult to gauge without further taint analysis on these specific output points.
In conclusion, the plugin's strength lies in its secure handling of database interactions and its clean vulnerability history. However, the presence of unprotected AJAX endpoints is a substantial security weakness that needs immediate attention. The unescaped output also warrants review. Addressing these specific areas would significantly improve the plugin's overall security posture.
Key Concerns
- AJAX handlers without auth checks
- Low percentage of properly escaped output
Marijuana Age Verify Security Vulnerabilities
Marijuana Age Verify Code Analysis
Bundled Libraries
Output Escaping
Marijuana Age Verify Attack Surface
AJAX Handlers 2
WordPress Hooks 31
Maintenance & Trust
Marijuana Age Verify Maintenance & Trust
Maintenance Signals
Community Trust
Marijuana Age Verify Alternatives
Age Gate Lite
age-gate-lite
A lightweight, customisable age gate to lock content from younger audience.
Age Gate
age-gate
A plugin to check the age of a visitor before view site or specified content
CPS | Age Verification
surbma-yes-no-popup
Shows a popup with age verification options. One of the best plugin for any membership or 18+ adult sites or any sites, that requires confirmation fro …
Age Gator
age-gate-plus
Age Gator is a Wordpress plugin specifically designed to guard sensitive content (alcohol, gambling, x-rated, etc) from underage users.
Age Verification Screen for WooCommerce
age-verification-screen-for-woocommerce
Easily add a customizable age verification screen to your store.
Marijuana Age Verify Developer Profile
7 plugins · 23K total installs
How We Detect Marijuana Age Verify
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/easy-marijuana-age-verify/includes/js/emav-admin-script.js/wp-content/plugins/easy-marijuana-age-verify/assets/css/emav-public.csseasy-marijuana-age-verify/includes/js/emav-admin-script.js?ver=easy-marijuana-age-verify/assets/css/emav-public.css?ver=HTML / DOM Fingerprints
emav-wrapperdata-emav-messagedata-emav-button-textdata-emav-background-colordata-emav-text-colordata-emav-button-colordata-emav-button-hover-color+6 moreemav_settings[emav_age_verify]