
GuardianKey Security & Risk Analysis
wordpress.org/plugins/guardiankeyGuardianKey is a service to protect systems in real-time against authentication attacks. It implements GK Auth Security for login protection and GKTin …
Is GuardianKey Safe to Use in 2026?
Generally Safe
Score 100/100GuardianKey has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The Guardian Key plugin v5.7 exhibits a mixed security posture. While it shows strong practices in avoiding dangerous functions and a clean vulnerability history with no recorded CVEs, several areas raise concerns. The presence of a REST API route without a permission callback represents a significant direct attack vector that could be exploited by unauthenticated users, leading to potential unauthorized actions or information disclosure. Furthermore, the taint analysis reveals flows with unsanitized paths, indicating a risk of handling user-supplied data in a way that could lead to vulnerabilities if not properly validated and sanitized before use. The absence of nonce checks, while not directly flagged as a vulnerability in this static analysis, is a common security control that is notably missing, potentially leaving certain operations open to replay attacks if they are critical and lack other authentication mechanisms.
Overall, the plugin's clean vulnerability history is a positive indicator, suggesting a generally careful development approach. However, the identified unprotected REST API endpoint and the unsanitized taint flows are critical findings that require immediate attention. The plugin's strengths lie in its limited attack surface beyond the REST API and its responsible use of SQL prepared statements and output escaping. Despite these strengths, the identified weaknesses, particularly the unprotected REST API, necessitate a cautious approach to its deployment until these issues are addressed.
Key Concerns
- REST API route without permission callback
- Taint flows with unsanitized paths
- Missing nonce checks
GuardianKey Security Vulnerabilities
GuardianKey Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
GuardianKey Attack Surface
REST API Routes 1
WordPress Hooks 27
Scheduled Events 2
Maintenance & Trust
GuardianKey Maintenance & Trust
Maintenance Signals
Community Trust
GuardianKey Alternatives
All-In-One Security (AIOS) – Security and Firewall
all-in-one-wp-security-and-firewall
Protect your website investment with All-In-One Security (AIOS) – a comprehensive and easy to use security plugin designed especially for WordPress.
Wordfence Login Security
wordfence-login-security
Secure your website with Wordfence Login Security, providing two-factor authentication, login and registration CAPTCHA, and XML-RPC protection.
Block wp-login
block-wp-login
This plugin completely blocks access to wp-login.php and creates a new secret login URL
IP & Country Blocker Lite
ip-blocker-lite
Advanced WordPress security plugin with IP/country blocking and two-factor authentication for comprehensive website protection.
Bearmor Security
bearmor-security
Lightweight, powerful WordPress security for small businesses. Malware scanning, login protection, 2FA, hardening - most features FREE.
GuardianKey Developer Profile
1 plugin · 20 total installs
How We Detect GuardianKey
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/guardiankey/assets/css/gk_login.css/wp-content/plugins/guardiankey/assets/js/gk_login.js/wp-content/plugins/guardiankey/assets/css/gk_admin.css/wp-content/plugins/guardiankey/assets/js/gk_admin.js/wp-content/plugins/guardiankey/assets/js/gk_login.js/wp-content/plugins/guardiankey/assets/js/gk_admin.jsHTML / DOM Fingerprints
gk-login-formgk-admin-formdata-gk-agentiddata-gk-keydata-gk-ivdata-gk-orgiddata-gk-authgroupiddata-gk-servicewindow.gk_login_obj/wp-json/guardiankey/v1/author/