
GDPR Notice Security & Risk Analysis
wordpress.org/plugins/gdpr-notice-originalGDPR Notice allows you, in accordance to the General Data Protection Regulation, to ask the user in advance if your page may use external services.
Is GDPR Notice Safe to Use in 2026?
Generally Safe
Score 85/100GDPR Notice has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "gdpr-notice-original" plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for SQL queries and has no recorded vulnerability history, suggesting a generally stable codebase. However, significant concerns arise from the static analysis. The plugin exposes two AJAX handlers with no authentication checks, creating a substantial attack surface for unauthorized actions. Furthermore, the taint analysis reveals that all analyzed flows involve unsanitized paths, although none are classified as critical or high severity, this still indicates a potential for unintended data manipulation or execution if these paths are reachable through user input.
The lack of proper output escaping on a notable percentage of outputs (60%) is another area of concern, potentially opening the door for cross-site scripting (XSS) vulnerabilities if user-supplied data is echoed directly to the browser without sanitization. While the plugin uses nonces and capability checks to some extent, the absence of authentication on critical entry points is the most immediate and pressing risk. The presence of the `exec` function, a dangerous function, is also noted, though its usage within the plugin's context isn't detailed in the provided data; however, it warrants careful scrutiny.
In conclusion, while the plugin benefits from clean SQL practices and a clean vulnerability history, the high number of unprotected AJAX endpoints and the presence of unsanitized paths are significant security weaknesses. Addressing these issues, particularly the unauthenticated AJAX handlers, should be the top priority to improve the plugin's overall security.
Key Concerns
- Unprotected AJAX handlers
- Flows with unsanitized paths
- Output escaping not properly implemented
- Dangerous function 'exec' present
GDPR Notice Security Vulnerabilities
GDPR Notice Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
GDPR Notice Attack Surface
AJAX Handlers 2
WordPress Hooks 39
Maintenance & Trust
GDPR Notice Maintenance & Trust
Maintenance Signals
Community Trust
GDPR Notice Alternatives
GDPR
gdpr
This plugin is meant to assist with the GDPR obligations of a Data processor and Controller.
CCM19 Integration
ccm19-integration
Integrates the CCM19 Cookie Consent Manager into WordPress. To use this plugin CCM19 needs to be bought or leased.
WP DSGVO Tools (GDPR)
shapepress-dsgvo
WP DSGVO Tools (GDPR) by legalweb.io help you to fulfill the GDPR (DSGVO) compliance guidance (GDPR)
My Agile Privacy® – CMP, Cookie Consent & Privacy Tools
myagileprivacy
Effortlessly set up cookie notices and privacy policies. Avoid fines by staying compliant with GDPR, nFADP, PIPEDA, LGPD, CCPA/CPRA and 14 more.
Smart Cookie Kit
smart-cookie-kit
Preventive blocking of third party cookies for GDPR/EU Cookie Law/ePrivacy. Translatable, cacheable, lightweight, powerful!
GDPR Notice Developer Profile
1 plugin · 20 total installs
How We Detect GDPR Notice
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gdpr-notice-original/css/gdpr.css/wp-content/plugins/gdpr-notice-original/js/gdpr.js/wp-content/plugins/gdpr-notice-original/js/gdpr.jsgdpr-notice-original/css/gdpr.css?ver=gdpr-notice-original/js/gdpr.js?ver=HTML / DOM Fingerprints
gdpr-notice-wrappergdpr-message-wrappergdpr-messagegdpr-cookiesdata-gdpr-cookie-namedata-gdpr-cookie-daysgdpr_settings/wp-json/gdpr-notice-original/v1/settings