
Go Dark Security & Risk Analysis
wordpress.org/plugins/go-darkThis SEO-Friendly plugin enables websites to 'go dark' on January 18th with a customizable message and start/end times to protest SOPA/PIPA …
Is Go Dark Safe to Use in 2026?
Generally Safe
Score 85/100Go Dark has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "go-dark" plugin version 1.0.7 exhibits a generally good security posture, primarily due to the absence of known vulnerabilities and a well-structured codebase with no identified critical or high severity taint flows. The plugin also demonstrates good practices by utilizing prepared statements for all SQL queries and including a nonce check, which is a positive indicator for preventing certain types of attacks.
However, a significant concern is the complete lack of output escaping across all observed outputs. This is a serious oversight that could allow for Cross-Site Scripting (XSS) vulnerabilities if any user-provided data is directly rendered to the page without sanitization. The absence of capability checks on any entry points is also a notable weakness, though currently mitigated by the plugin's limited attack surface. The plugin's vulnerability history being completely clean is a strong positive, suggesting good development practices and thorough testing.
In conclusion, while "go-dark" v1.0.7 benefits from a clean vulnerability record and secure data handling for SQL, the critical deficiency in output escaping presents a substantial risk. This needs immediate attention to prevent potential XSS exploits. The lack of capability checks on its zero-entry-point attack surface is less concerning for now but should be a consideration for future development.
Key Concerns
- All output is unescaped
- No capability checks on entry points
Go Dark Security Vulnerabilities
Go Dark Code Analysis
Output Escaping
Data Flow Analysis
Go Dark Attack Surface
WordPress Hooks 3
Maintenance & Trust
Go Dark Maintenance & Trust
Maintenance Signals
Community Trust
Go Dark Alternatives
SOPA Blackout Plugin
sopa-blackout-plugin
This plugin allows you to set SOPA blackout dates for your WordPress website. SEO friendly plus easy options to configure how often it's shown.
pensopay Payments
woo-pensopay
Integrates the pensopay payment gateway into your WooCommerce installation.
pensopay Payments v2
pensopay-payments-v2
Integrates your pensopay V2 payment gateway into your WooCommerce installation.
Multibanco / MB Way / Payshop / Cofidis Pay (by LUSOPAY) for WooCommerce
multibanco-e-ou-payshop-by-lusopay
WooCommerce plugin for MULTIBANCO, PAYSHOP, MB Way and Cofidis Pay. It allows to send SMS and e-mail to the customer with payment details.
Stop SOPA
stop-sopa
This plugin adds small protest box to your website and switch it to "Blackout Day" mode on 18th January 2012.
Go Dark Developer Profile
16 plugins · 16K total installs
How We Detect Go Dark
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/go-dark/blocked.png/wp-content/plugins/go-dark/seal.png/wp-content/plugins/go-dark/wood.jpgHTML / DOM Fingerprints
wrapicon32add-new-h2form-table<!-- ... -->data-editorwindow.go_dark<div id="blocked">