
Goracash Security & Risk Analysis
wordpress.org/plugins/goracashGoracash, part of Wengo - Vivendi Group, is an affiliate program that allows you to monetize your traffic and earn money with it.
Is Goracash Safe to Use in 2026?
Use With Caution
Score 63/100Goracash has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The goracash v1.1 plugin exhibits a mixed security posture. While it demonstrates good practices by not using dangerous functions and exclusively employing prepared statements for SQL queries, significant concerns arise from its output escaping and vulnerability history. The complete absence of proper output escaping for all 15 identified output points is a critical weakness, leaving the plugin highly susceptible to Cross-Site Scripting (XSS) attacks. This is further exacerbated by the plugin's history, which includes a known medium-severity XSS vulnerability that remains unpatched. The presence of an unpatched CVE, especially related to XSS, is a major red flag. The limited attack surface and lack of directly exploitable AJAX or REST API endpoints without permission checks are positive aspects, but they are overshadowed by the fundamental flaws in output handling and the unresolved historical vulnerability.
Key Concerns
- Unpatched CVE exists
- No output escaping
- No nonce checks
- No capability checks
Goracash Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Goracash <= 1.1 - Authenticated (Administrator+) Stored Cross-Site Scripting
Goracash Release Timeline
Goracash Code Analysis
Output Escaping
Goracash Attack Surface
Shortcodes 3
WordPress Hooks 8
Maintenance & Trust
Goracash Maintenance & Trust
Maintenance Signals
Community Trust
Goracash Alternatives
AdSpeed Ad Server
adspeed-ad-server
This plugin displays ads from your AdSpeed account on the sidebar or within a post. Ads are served, managed and tracked for impressions and clicks by …
Eldolink®
eldolink
Eldolink® is an affiliate program that allows you to monetize your traffic. Original wellness contents & products. Win big with Slimdoo®.
mySimpleAds WordPress Ad Manager
mysimpleads-wordpress-ad-manager
The wordpress plugin will allow you to easily place your mySimpleAds Ads anywhere into posts, pages, or templates.
CookieYes – Cookie Banner for Cookie Consent (Easy to setup GDPR/CCPA Compliant Cookie Notice)
cookie-law-info
Easily set up cookie banner or notice in WordPress, and policy pages for compliance with global cookie laws (GDPR, DSGVO, RGPD, CCPA/CPRA, etc).
Hostinger Reach – AI-Powered Email Marketing for WordPress
hostinger-reach
Launch and grow your email marketing effortlessly with Hostinger Reach. Collect contacts, sync subscribers, and send emails – all in one, AI powered.
Goracash Developer Profile
1 plugin · 300 total installs
How We Detect Goracash
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/goracash/css/bootstrap.min.css/wp-content/plugins/goracash/css/font-awesome.min.css/wp-content/plugins/goracash/css/admin.css/wp-content/plugins/goracash/js/admin.js/wp-content/plugins/goracash/js/admin.jsgoracash_admin_bootstrap_css?ver=3.3.5goracash_admin_fontaweome_css?ver=4.4.0goracash_admin_css?ver=0.1goracash_admin_js?ver=0.1HTML / DOM Fingerprints
alert-warning