
getLaw WP API Client Security & Risk Analysis
wordpress.org/plugins/getlaw-wp-api-clientWith this Plugin you can automatically embed legal texts of the Legal-Tech-Platform www.getLaw.de in your website and your shop.
Is getLaw WP API Client Safe to Use in 2026?
Generally Safe
Score 100/100getLaw WP API Client has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The getlaw-wp-api-client plugin version 1.1.4 exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, raw SQL queries, file operations, and an external HTTP request is commendable. Furthermore, all detected outputs are properly escaped, and the plugin utilizes prepared statements for its SQL queries, indicating good development practices in these areas. The plugin also demonstrates a conscious effort to implement capability checks, which is a positive sign for access control.
However, a significant concern arises from the complete lack of nonce checks across all identified entry points, particularly the single shortcode. While the static analysis reports 0 unprotected entry points, the absence of nonce verification for the shortcode means that its functionality could potentially be triggered by an attacker without proper user authorization or intent. The limited attack surface is a mitigating factor, but this oversight remains a potential avenue for exploitation. The plugin's vulnerability history is clean, with no recorded CVEs, which suggests either a lack of past issues or a strong security focus from the developers. Despite the clean history, the potential risk from the missing nonce check cannot be overlooked.
Key Concerns
- Missing nonce checks on shortcode
getLaw WP API Client Security Vulnerabilities
getLaw WP API Client Code Analysis
Output Escaping
getLaw WP API Client Attack Surface
Shortcodes 1
WordPress Hooks 6
Maintenance & Trust
getLaw WP API Client Maintenance & Trust
Maintenance Signals
Community Trust
getLaw WP API Client Alternatives
Janolaw AGB Hosting
janolaw-agb-hosting
This plugin gets legal documents provided by janolaw AG (commercial service) like General terms, Imprint etc. for Wordpress sites and WooCommerce shop …
Legal Text Connector of the IT-Recht Kanzlei
legal-texts-connector-it-recht-kanzlei
Ensures that your website is always provided with warning-proof legal texts from IT-Recht Kanzlei after booking the GTC service.
wpShopGermany IT-RECHT KANZLEI
wpshopgermany-it-recht-kanzlei
Mit Hilfe dieses Plugins ist es möglich deutsche rechtssichere Texte (für Shops) über eine API zu aktualisieren.
wpShopGermany – Händlerbund
wpshopgermany-handlerbund
Mit Hilfe dieses Plugins ist es möglich deutsche rechtssichere Texte (für Shops) zu aktualisieren. Die Texte werden vom Händlerbund bezogen.
Impressum
impressum
Impressum provides you with a full-fledged easy to use imprint generator right within your WordPress site.
getLaw WP API Client Developer Profile
1 plugin · 600 total installs
How We Detect getLaw WP API Client
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/getlaw-wp-api-client/getlaw.cssHTML / DOM Fingerprints
button-getlawgetlaw_imprint_keygetlaw_imprint_shortcodegetlaw_imprint_manual_updategetlaw_privacy_keygetlaw_privacy_shortcodegetlaw_privacy_manual_update+9 more[getlaw text='impressum'][getlaw text='datenschutz'][getlaw text='agb'][getlaw text='widerruf']