
GDPR Data Request Form Security & Risk Analysis
wordpress.org/plugins/gdpr-data-request-formUse WordPress Core GDPR tools to build front-end Personal Data export/erasure forms (includes Widget, Gutenberg Block, shortcode & Hooks).
Is GDPR Data Request Form Safe to Use in 2026?
Generally Safe
Score 100/100GDPR Data Request Form has a strong security track record. Known vulnerabilities have been patched promptly.
The gdpr-data-request-form plugin v1.7 exhibits a generally strong security posture with several good practices evident in the static analysis. Notably, all SQL queries are prepared statements, and a very high percentage of outputs are properly escaped, significantly reducing the risk of common web vulnerabilities like SQL injection and cross-site scripting. The plugin also lacks dangerous functions, file operations, and external HTTP requests, further minimizing its attack surface. The absence of any unpatched vulnerabilities in its history is also a positive sign.
However, there are a couple of areas that warrant attention. The presence of two 'flows with unsanitized paths' in the taint analysis, while not classified as critical or high severity, suggests a potential for insecure handling of file paths or user-supplied input that could be used to manipulate file access. Additionally, the complete absence of capability checks on its entry points is a significant concern. While AJAX handlers and shortcodes are present, the lack of explicit permission checks means that any authenticated user, regardless of their role, could potentially trigger these functionalities. This could lead to unintended actions or data exposure if the functionality is sensitive.
Overall, the plugin has a solid foundation in secure coding practices, particularly concerning database interactions and output handling. The historical data also indicates a responsible approach to vulnerability management. The main weaknesses lie in the potential for path-related issues identified in the taint analysis and the critical omission of capability checks on its entry points, which represent a notable risk that could be exploited by authenticated but unauthorized users.
Key Concerns
- Flows with unsanitized paths
- No capability checks on entry points
GDPR Data Request Form Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
GDPR Data Request Form <= 1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting
GDPR Data Request Form Code Analysis
Output Escaping
Data Flow Analysis
GDPR Data Request Form Attack Surface
AJAX Handlers 4
Shortcodes 2
WordPress Hooks 9
Maintenance & Trust
GDPR Data Request Form Maintenance & Trust
Maintenance Signals
Community Trust
GDPR Data Request Form Alternatives
Dismiss Privacy Nag
dismiss-privacy-nag
dismiss privacy pointer nag and admin notification when it is activated or if it is in mu-plugins directory
Dismiss Privacy Tools
dismiss-privacy-tools
disable and remove privacy tools added in 4.9.6 completely GDPR OFF reset options to default when it is activated or if it is in mu-plugins directory
Complianz – GDPR/CCPA Cookie Consent
complianz-gdpr
Configure your Cookie Banner, Cookie Consent and Cookie Policy with our Wizard and Cookies Scan.
Cookie Notice & Compliance for GDPR / CCPA
cookie-notice
Cookie Notice allows you to you elegantly inform users that your site uses cookies and helps you comply with GDPR, CCPA and other data privacy laws.
Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative)
burst-statistics
Analytics you'll actually use. Privacy-friendly, zero config, and designed to be actionable. Get insights, not just raw data.
GDPR Data Request Form Developer Profile
24 plugins · 64K total installs
How We Detect GDPR Data Request Form
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gdpr-data-request-form/public/css/public.css/wp-content/plugins/gdpr-data-request-form/public/js/gdrf-public.js/wp-content/plugins/gdpr-data-request-form/includes/js/gdrf-admin.jsjs/gdrf-admin.jsgdpr-data-request-form/public/css/public.css?ver=gdpr-data-request-form/public/js/gdrf-public.js?ver=HTML / DOM Fingerprints
gdrf-fieldgdrf-field-actiongdrf-data-type-inputgdrf-data-type-labelgdrf-field-emailgdrf-field-humangdrf-field-submitgdrf_data_human_keygdrf_data_noncegdrf_data_typegdrf-data-type-exportgdrf-data-type-removegdrf_data_email+1 moregdrf_settingsgdrf_localize/wp-json/wp/v2/users