GhostTrap Security & Risk Analysis

wordpress.org/plugins/ghosttrap

Advanced 5-layer invisible spam protection for comments. No captcha, no user friction - professional spam blocking.

20 active installs v1.0.3 PHP 7.4+ WP 5.0+ Updated Feb 8, 2026
antispamcommentsprotectionsecurityspam
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is GhostTrap Safe to Use in 2026?

Generally Safe

Score 100/100

GhostTrap has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The ghosttrap plugin v1.0.3 exhibits a strong security posture based on the provided static analysis. It demonstrates excellent adherence to secure coding practices, with no identified dangerous functions, raw SQL queries, or file operations. The high percentage of properly escaped output and the presence of nonce and capability checks on all identified entry points (one AJAX handler) are particularly commendable. The absence of any known vulnerabilities or CVEs in its history further contributes to a positive security outlook. The taint analysis showing zero flows with unsanitized paths reinforces the confidence in its secure handling of data.

Vulnerabilities
None known

GhostTrap Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

GhostTrap Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
12
70 escaped
Nonce Checks
6
Capability Checks
8
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

85% escaped82 total outputs
Attack Surface

GhostTrap Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_ghosttrap_reset_statsincludes\ghosttrap-settings.php:291
WordPress Hooks 24
actionwp_enqueue_scriptsghosttrap.php:100
actioncomment_form_beforeghosttrap.php:101
actioncomment_formghosttrap.php:102
actioncomment_formghosttrap.php:103
filterpreprocess_commentghosttrap.php:306
filterplugin_action_linksghosttrap.php:328
filterplugin_row_metaghosttrap.php:352
actionadmin_enqueue_scriptsincludes\ghosttrap-info.php:42
actionadmin_enqueue_scriptsincludes\ghosttrap-info.php:85
actionadmin_noticesincludes\ghosttrap-info.php:156
actionadmin_noticesincludes\ghosttrap-info.php:199
actionadmin_initincludes\ghosttrap-info.php:234
actioncurrent_screenincludes\ghosttrap-info.php:271
filterdashboard_glance_itemsincludes\ghosttrap-info.php:301
actionadmin_bar_menuincludes\ghosttrap-info.php:360
actionadmin_menuincludes\ghosttrap-settings.php:39
actionadmin_enqueue_scriptsincludes\ghosttrap-settings.php:75
actionadmin_noticesincludes\ghosttrap-settings.php:96
actionadmin_noticesincludes\ghosttrap-settings.php:104
actionadmin_noticesincludes\ghosttrap-settings.php:142
actionadmin_noticesincludes\ghosttrap-settings.php:146
actionadmin_initincludes\ghosttrap-settings.php:151
actionadmin_initincludes\ghosttrap-settings.php:212
actionadmin_initincludes\ghosttrap-settings.php:254
Maintenance & Trust

GhostTrap Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 8, 2026
PHP min version7.4
Downloads272

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

GhostTrap Developer Profile

LaughterOnWater

7 plugins · 70 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect GhostTrap

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ghosttrap/assets/js/ghosttrap.js/wp-content/plugins/ghosttrap/assets/js/ghosttrap-form.js/wp-content/plugins/ghosttrap/assets/css/ghosttrap-frontend.css
Script Paths
assets/js/ghosttrap.jsassets/js/ghosttrap-form.js
Version Parameters
ghosttrap.js?ver=ghosttrap-form.js?ver=ghosttrap-frontend.css?ver=

HTML / DOM Fingerprints

CSS Classes
ghosttrap-js-fallbackghosttrap-js-required-messageghosttrap-js-required-titleghosttrap-js-required-textghosttrap-js-required-note
HTML Comments
<!-- GhostTrap v<!-- GhostTrap v
Data Attributes
id="ghosttrap-js-check"id="ghosttrap-js-nonce"id="ghosttrap-comment-form-container"
JS Globals
window.ghosttrap_data
FAQ

Frequently Asked Questions about GhostTrap