GCheck – WordPress Certificate Plugin & Verification System Security & Risk Analysis

wordpress.org/plugins/gcheck-certificate

The ultimate WordPress Certificate Plugin. Issue, manage, and verify certificates with Google Sheets, CSV, and REST API.

100 active installs v1.3.6 PHP 7.2+ WP 5.0+ Updated Jan 22, 2026
certificatecourseeducationlmsverification
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is GCheck – WordPress Certificate Plugin & Verification System Safe to Use in 2026?

Generally Safe

Score 100/100

GCheck – WordPress Certificate Plugin & Verification System has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "gcheck-certificate" plugin version 1.3.6 exhibits a generally good security posture based on the provided static analysis. The plugin has a limited attack surface, with all identified entry points (AJAX handlers, shortcodes) protected by authentication checks. Furthermore, the plugin demonstrates strong practices with a high percentage of SQL queries using prepared statements and a significant number of nonce and capability checks. The absence of dangerous functions, external HTTP requests, and file operations are all positive indicators. The taint analysis also shows no critical or high-severity unsanitized flows, which is a strong sign of secure code handling user input. The plugin's vulnerability history being completely clean further reinforces its current security standing. However, the most significant concern lies in the output escaping. With 36% of outputs properly escaped, there's a substantial portion that is not, indicating a potential risk for cross-site scripting (XSS) vulnerabilities if user-controlled data is directly echoed without proper sanitization. While no current vulnerabilities or critical taint flows are evident, this weakness warrants attention.

Key Concerns

  • Low percentage of properly escaped output
Vulnerabilities
None known

GCheck – WordPress Certificate Plugin & Verification System Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

GCheck – WordPress Certificate Plugin & Verification System Code Analysis

Dangerous Functions
0
Raw SQL Queries
10
78 prepared
Unescaped Output
568
324 escaped
Nonce Checks
16
Capability Checks
24
File Operations
2
External Requests
0
Bundled Libraries
0

SQL Query Safety

89% prepared88 total queries

Output Escaping

36% escaped892 total outputs
Data Flows
All sanitized

Data Flow Analysis

16 flows
render_certificate_page (includes\class-gcheck-admin.php:401)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

GCheck – WordPress Certificate Plugin & Verification System Attack Surface

Entry Points6
Unprotected0

AJAX Handlers 4

authwp_ajax_gcheck_validate_certificateincludes\class-gcheck-frontend.php:18
noprivwp_ajax_gcheck_validate_certificateincludes\class-gcheck-frontend.php:19
authwp_ajax_gcheck_validate_certificatetrunk\includes\class-gcheck-frontend.php:18
noprivwp_ajax_gcheck_validate_certificatetrunk\includes\class-gcheck-frontend.php:19

Shortcodes 2

[validate_certificate_form] includes\class-gcheck-frontend.php:22
[validate_certificate_form] trunk\includes\class-gcheck-frontend.php:22
WordPress Hooks 20
actionplugins_loadedgcheck-certificate.php:125
actionplugins_loadedgcheck-certificate.php:137
actionplugins_loadedgcheck-certificate.php:145
actionadmin_menuincludes\class-gcheck-admin.php:15
actionadmin_post_gcheck_export_certificatesincludes\class-gcheck-admin.php:16
actionadmin_post_gcheck_bulk_uploadincludes\class-gcheck-admin.php:17
actionadmin_enqueue_scriptsincludes\class-gcheck-admin.php:18
actionwp_enqueue_scriptsincludes\class-gcheck-frontend.php:15
actionrest_api_initincludes\class-gcheck-rest-api.php:17
actionadmin_initincludes\settings-page.php:32
actionplugins_loadedtrunk\gcheck-certificate.php:125
actionplugins_loadedtrunk\gcheck-certificate.php:137
actionplugins_loadedtrunk\gcheck-certificate.php:145
actionadmin_menutrunk\includes\class-gcheck-admin.php:15
actionadmin_post_gcheck_export_certificatestrunk\includes\class-gcheck-admin.php:16
actionadmin_post_gcheck_bulk_uploadtrunk\includes\class-gcheck-admin.php:17
actionadmin_enqueue_scriptstrunk\includes\class-gcheck-admin.php:18
actionwp_enqueue_scriptstrunk\includes\class-gcheck-frontend.php:15
actionrest_api_inittrunk\includes\class-gcheck-rest-api.php:17
actionadmin_inittrunk\includes\settings-page.php:32
Maintenance & Trust

GCheck – WordPress Certificate Plugin & Verification System Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJan 22, 2026
PHP min version7.2
Downloads2K

Community Trust

Rating100/100
Number of ratings2
Active installs100
Developer Profile

GCheck – WordPress Certificate Plugin & Verification System Developer Profile

mhamoudaa

1 plugin · 100 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect GCheck – WordPress Certificate Plugin & Verification System

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gcheck-certificate/assets/css/gcheck-certificate-admin.css/wp-content/plugins/gcheck-certificate/assets/js/gcheck-certificate-admin.js/wp-content/plugins/gcheck-certificate/assets/css/gcheck-certificate-frontend.css/wp-content/plugins/gcheck-certificate/assets/js/gcheck-certificate-frontend.js/wp-content/plugins/gcheck-certificate/assets/css/gcheck-certificate-verification.css/wp-content/plugins/gcheck-certificate/assets/js/gcheck-certificate-verification.js
Script Paths
/wp-content/plugins/gcheck-certificate/assets/js/gcheck-certificate-admin.js/wp-content/plugins/gcheck-certificate/assets/js/gcheck-certificate-frontend.js/wp-content/plugins/gcheck-certificate/assets/js/gcheck-certificate-verification.js
Version Parameters
gcheck-certificate/assets/css/gcheck-certificate-admin.css?ver=gcheck-certificate/assets/js/gcheck-certificate-admin.js?ver=gcheck-certificate/assets/css/gcheck-certificate-frontend.css?ver=gcheck-certificate/assets/js/gcheck-certificate-frontend.js?ver=gcheck-certificate/assets/css/gcheck-certificate-verification.css?ver=gcheck-certificate/assets/js/gcheck-certificate-verification.js?ver=

HTML / DOM Fingerprints

CSS Classes
gcheck-certificate-admin-wrapgcheck-certificate-frontend-formgcheck-certificate-verification-form
Data Attributes
data-gcheck-certificate-ajax-url
JS Globals
gcheckCertificateAdmingcheckCertificateFrontendgcheckCertificateVerification
REST Endpoints
/wp-json/gcheck-certificate/v1/verify
FAQ

Frequently Asked Questions about GCheck – WordPress Certificate Plugin & Verification System