Gryphon Verified Client IP Security & Risk Analysis

wordpress.org/plugins/gryphon-verified-client-ip

Determines the true client IP by verifying Forwarded and similar headers, traversing only trusted proxy hops.

0 active installs v1.2.1 PHP 8.1+ WP 6.4+ Updated Apr 13, 2026
client-ipip-addressproxyuser-ipvisitor-ip
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Gryphon Verified Client IP Safe to Use in 2026?

Generally Safe

Score 100/100

Gryphon Verified Client IP has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The 'gryphon-verified-client-ip' v1.2.1 plugin exhibits a generally strong security posture from a static analysis perspective, with no identified dangerous functions, SQL injection vulnerabilities, or file operations. The absence of any recorded CVEs further contributes to this positive outlook. However, a significant concern arises from the complete lack of output escaping. With 94 total outputs and 0% properly escaped, this creates a high risk for cross-site scripting (XSS) vulnerabilities. Any data processed or displayed by the plugin, if not meticulously sanitized by external means, could be exploited to inject malicious scripts into a user's browser. While the plugin appears to have a minimal attack surface and no obvious vulnerabilities in its history, the unescaped output is a critical oversight that severely undermines its security.

The plugin's lack of any detected taint flows or critical/high severity issues is a positive indicator, suggesting that direct code execution or data manipulation vulnerabilities are unlikely based on the static analysis. The fact that all SQL queries use prepared statements is also a commendable security practice. Despite these strengths, the critical flaw in output escaping means that the plugin is susceptible to XSS attacks. Therefore, while the plugin has a clean vulnerability history and a limited attack surface, the unescaped output presents a clear and present danger to users.

In conclusion, the 'gryphon-verified-client-ip' v1.2.1 plugin demonstrates good practices in areas like SQL query handling and a lack of known vulnerabilities. However, the complete absence of output escaping is a major security weakness that requires immediate attention. This oversight creates a significant risk of XSS vulnerabilities, overshadowing the plugin's otherwise positive security attributes.

Key Concerns

  • Unescaped output detected
Vulnerabilities
None known

Gryphon Verified Client IP Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Gryphon Verified Client IP Release Timeline

v1.2.1Current
v1.2.0
Code Analysis
Analyzed Apr 16, 2026

Gryphon Verified Client IP Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
94
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped94 total outputs
Attack Surface

Gryphon Verified Client IP Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionplugins_loadedgryphon-verified-client-ip.php:42
Maintenance & Trust

Gryphon Verified Client IP Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedApr 13, 2026
PHP min version8.1
Downloads61

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Gryphon Verified Client IP Developer Profile

Sly Gryphon

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Gryphon Verified Client IP

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gryphon-verified-client-ip/assets/css/admin-schemes.css/wp-content/plugins/gryphon-verified-client-ip/assets/js/admin-schemes.js/wp-content/plugins/gryphon-verified-client-ip/assets/js/admin-diagnostics.js
Script Paths
/wp-content/plugins/gryphon-verified-client-ip/assets/js/admin-schemes.js/wp-content/plugins/gryphon-verified-client-ip/assets/js/admin-diagnostics.js
Version Parameters
gryphon-verified-client-ip/assets/css/admin-schemes.css?ver=gryphon-verified-client-ip/assets/js/admin-schemes.js?ver=gryphon-verified-client-ip/assets/js/admin-diagnostics.js?ver=

HTML / DOM Fingerprints

CSS Classes
vcip-admin-schemesvcip-admin-diagnostics
Data Attributes
data-vcip-schemes
JS Globals
vcipI18nvcipSchemeTemplate
FAQ

Frequently Asked Questions about Gryphon Verified Client IP