GDPR ✔Check Security & Risk Analysis

wordpress.org/plugins/gdpr-check

Is your site EU GPDR ready?

50 active installs v1.0.1 PHP + WP + Updated Mar 30, 2018
admineugpdrlawpolicy
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is GDPR ✔Check Safe to Use in 2026?

Generally Safe

Score 85/100

GDPR ✔Check has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The 'gdpr-check' plugin version 1.0.1 exhibits a generally positive security posture, particularly in its handling of database queries and lack of file operations or external HTTP requests. The absence of known CVEs and a clean vulnerability history further contribute to this positive outlook. However, the static analysis reveals significant concerns regarding output escaping. With only 9% of outputs properly escaped out of 66 total outputs analyzed, there is a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. While the taint analysis shows no critical or high severity issues, the presence of two flows with unsanitized paths, although not resulting in critical findings, warrants attention as they could potentially be exploited if the plugin's functionality evolves or interacts with other components in unexpected ways. The lack of any capability checks or nonce checks on its entry points, while currently not a direct issue due to the absence of entry points, represents a potential future risk if new functionalities are added without proper security considerations. Overall, the plugin has strong foundations but suffers from a critical weakness in output sanitization that needs immediate attention.

Key Concerns

  • Insufficient output escaping
  • Taint flows with unsanitized paths
Vulnerabilities
None known

GDPR ✔Check Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

GDPR ✔Check Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
60
6 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

9% escaped66 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
gdprcompatible_save_status (code.php:46)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

GDPR ✔Check Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_menucode.php:36
actionadmin_post_gdprcompatible_save_statuscode.php:45
actionadmin_initcode.php:95
Maintenance & Trust

GDPR ✔Check Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedMar 30, 2018
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs50
Developer Profile

GDPR ✔Check Developer Profile

dpoakaspine

9 plugins · 630 total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect GDPR ✔Check

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about GDPR ✔Check