
GP Add GP Profile to WP Profile Security & Risk Analysis
wordpress.org/plugins/gp-add-gp-profile-to-wp-profileA plugin for GlotPress as a WordPress Plugin that adds the GlotPress user profile settings to the WordPress profile page.
Is GP Add GP Profile to WP Profile Safe to Use in 2026?
Generally Safe
Score 85/100GP Add GP Profile to WP Profile has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of gp-add-gp-profile-to-wp-profile v0.6 reveals a strong adherence to WordPress security best practices. The absence of any identified attack surface points, dangerous functions, raw SQL queries, unescaped output, file operations, external HTTP requests, or taint flows with unsanitized paths is highly commendable. The plugin also correctly utilizes capability checks, indicating a good understanding of WordPress's role-based access control system. The vulnerability history being clean further reinforces a positive security posture.
However, the lack of any nonces is a notable concern. While the current analysis doesn't reveal immediate exploitable vulnerabilities, nonce checks are a fundamental security layer against Cross-Site Request Forgery (CSRF) attacks. The absence of any AJAX handlers or REST API routes without auth checks is a strength, but the plugin's overall limited entry points mean that any future additions could introduce new risks if not properly secured.
In conclusion, this plugin exhibits excellent security hygiene in its current state, with no critical or high-risk issues detected. The primary area for improvement is the implementation of nonce checks, which would further strengthen its defenses against a common class of web vulnerabilities. The clean vulnerability history suggests a well-maintained codebase, but ongoing vigilance and the addition of nonce checks are recommended.
Key Concerns
- Missing nonce checks
GP Add GP Profile to WP Profile Security Vulnerabilities
GP Add GP Profile to WP Profile Code Analysis
GP Add GP Profile to WP Profile Attack Surface
WordPress Hooks 5
Maintenance & Trust
GP Add GP Profile to WP Profile Maintenance & Trust
Maintenance Signals
Community Trust
GP Add GP Profile to WP Profile Alternatives
Localize WordPress
localize
Easily switch to any localization from GlotPress
WP Translation Status
wp-translation
Make a link to GlotPress centralised translation so contributor can help translating the plugin that do not have yet a translation in the local site l …
GP Remove Powered By
gp-removed-powered-by
A plugin for GlotPress as a WordPress plugin that removes the "Powered By" in the footer.
GP Additional Links
gp-additional-links
A plugin for GlotPress as a WordPress plugin that adds a link to the WordPress dashboard for admins in the GlotPress page as well as a link to the Glo …
GP Download Name
gp-download-name
A plugin for GlotPress that uses a customizable template for the download file name.
GP Add GP Profile to WP Profile Developer Profile
34 plugins · 8K total installs
How We Detect GP Add GP Profile to WP Profile
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
gp-profile