
GP – GeePress Security & Risk Analysis
wordpress.org/plugins/gpAll the tools you need to integrate your WordPress and Google+.
Is GP – GeePress Safe to Use in 2026?
Generally Safe
Score 85/100GP – GeePress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "gp" v1.0 plugin exhibits a mixed security posture. While it demonstrates good practices in handling SQL queries with prepared statements and avoids critical taint flows, several significant security concerns are present. The plugin has a small but concerning attack surface, with two AJAX handlers, both of which lack authentication checks. This directly exposes potentially sensitive functionality to unauthenticated users. Additionally, the code signals indicate the use of dangerous functions like 'unserialize' and 'create_function', which can be exploited if user-controlled data is passed to them. The low percentage of properly escaped output further exacerbates these risks, as it opens the door for Cross-Site Scripting (XSS) vulnerabilities. The absence of any recorded vulnerability history is a positive sign, suggesting it has not been a target or has not had publicly disclosed vulnerabilities. However, this cannot compensate for the immediate risks identified in the code analysis, particularly the unprotected AJAX endpoints and the use of dangerous functions.
Key Concerns
- AJAX handlers without auth checks
- Use of dangerous functions (unserialize, create_function)
- Low output escaping percentage
GP – GeePress Security Vulnerabilities
GP – GeePress Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
GP – GeePress Attack Surface
AJAX Handlers 2
WordPress Hooks 32
Maintenance & Trust
GP – GeePress Maintenance & Trust
Maintenance Signals
Community Trust
GP – GeePress Alternatives
One Click Close Comments
one-click-close-comments
Conveniently close or open comments for a post or page with one click from the admin listing of posts.
chat-me-now
chat-me-now
Floating button that opens the WhatsApp chat to the technical support on turn. It allows asign the work schedule up to 2 employees.
Relative URL
relative-url
Relative URL applies wp_make_link_relative function to links to convert them to relative URLs.
Quotmarks Replacer
quotmarks-replacer
Quotmarks Replacer disables wptexturize function that keeps all quotation marks and suspension points in half-width form.
Nofollow Case by Case
nofollow-case-by-case
"Dofollow" but Nofollow Case by Case allows you to selectively apply nofollow to your comments as well.
GP – GeePress Developer Profile
7 plugins · 8K total installs
How We Detect GP – GeePress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gp/google-api/Google_Client.php/wp-content/plugins/gp/google-api/contrib/Google_PlusService.php/wp-content/plugins/gp/google-api/contrib/Google_Oauth2Service.php/wp-content/plugins/gp/wp-oauth.phpgp/style.css?ver=HTML / DOM Fingerprints
<!--
if you want to force the plugin to use a client id and secret,
add your keys and copy the following 2 lines to your wp-config.php
-->data-gp-google-client-iddata-gp-google-client-secretwindow.gp_client_idwindow.gp_client_secret