
Gwolle Guestbook Security & Risk Analysis
wordpress.org/plugins/gwolle-gbGwolle Guestbook is the WordPress guestbook you've just been looking for. Beautiful and easy.
Is Gwolle Guestbook Safe to Use in 2026?
Generally Safe
Score 89/100Gwolle Guestbook has a strong security track record. Known vulnerabilities have been patched promptly.
The "gwolle-gb" plugin exhibits a mixed security posture. While it demonstrates good practices such as a significant number of nonce and capability checks, and a reasonable percentage of SQL queries using prepared statements, several concerning areas are present. The static analysis reveals a substantial attack surface, particularly with 6 out of 7 AJAX handlers lacking authentication checks. Although no critical or high severity taint flows were identified, the presence of 2 flows with unsanitized paths warrants attention as they could potentially lead to vulnerabilities if not handled carefully. The plugin's history of 7 known CVEs, including past critical and high severity issues like Cross-Site Scripting, CSRF, and PHP Remote File Inclusion, is a significant concern. The fact that there are currently no unpatched vulnerabilities is positive, but the historical pattern suggests a recurring tendency for vulnerabilities to be introduced or discovered. The plugin's last reported vulnerability was in July 2025, which is concerning as it implies recent issues or a delayed reporting mechanism.
Key Concerns
- Unprotected AJAX handlers
- Unsanitized paths in taint flows
- History of critical CVEs
- History of high CVEs
- History of medium CVEs
- Recent vulnerability reported (2025-07-09)
Gwolle Guestbook Security Vulnerabilities
CVEs by Year
Severity Breakdown
7 total CVEs
Gwolle Guestbook <= 4.9.2 - Unauthenticated Stored Cross-Site Scripting via `gwolle_gb_content` Parameter
Gwolle Guestbook <= 4.7.1 - Reflected Cross-Site Scripting
Gwolle Guestbook <= 4.1.2 - Reflected Cross-Site Scripting
Gwolle Guestbook <= 2.5.3 - Cross-Site Scripting
Gwolle Guestbook <= 2.1.0 - Stored Cross-Site Scripting
Gwolle Guestbook <= 2.1.0 - Cross-Site Request Forgery
Gwolle Guestbook <= 1.5.3 - Remote File Inclusion
Gwolle Guestbook Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Gwolle Guestbook Attack Surface
AJAX Handlers 7
Shortcodes 5
WordPress Hooks 48
Maintenance & Trust
Gwolle Guestbook Maintenance & Trust
Maintenance Signals
Community Trust
Gwolle Guestbook Alternatives
Memorista
memorista
Offer guestbook functionality on any WordPress site in just a few steps.
LIBRO DE VISITAS – GUESTBOOK
libro-de-visitas-guestbook
For live example click here!!!
Widgets for Google Reviews
wp-reviews-plugin-for-google
Embed Google reviews fast and easily into your WordPress site. Increase SEO, trust and sales using Google reviews.
MW WP Form
mw-wp-form
MW WP Form is shortcode base contact form plugin. This plugin have many features. For example you can use many validation rules, inquiry data saving, …
Public Post Preview
public-post-preview
Allow anonymous users to preview a draft of a post before it is published.
Gwolle Guestbook Developer Profile
18 plugins · 82K total installs
How We Detect Gwolle Guestbook
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gwolle-gb/frontend/css/gwolle-gb-frontend.css/wp-content/plugins/gwolle-gb/frontend/css/gwolle-gb-widget.css/wp-content/plugins/gwolle-gb/frontend/js/gwolle-gb-frontend.js/wp-content/plugins/gwolle-gb/frontend/js/gwolle-gb-widget.js/wp-content/plugins/gwolle-gb/frontend/js/gwolle-gb-frontend.js/wp-content/plugins/gwolle-gb/frontend/js/gwolle-gb-widget.jsgwolle-gb/frontend/css/gwolle-gb-frontend.css?ver=gwolle-gb/frontend/css/gwolle-gb-widget.css?ver=gwolle-gb/frontend/js/gwolle-gb-frontend.js?ver=gwolle-gb/frontend/js/gwolle-gb-widget.js?ver=HTML / DOM Fingerprints
gwolle-gbgwolle-gb-formgwolle-gb-entriesgwolle-gb-entrygwolle-gb-widget-wrapperGwolle Guestbookend Gwolle Guestbookdata-gwolle-gb-form-idgwolle_gb_frontend_paramsgwolle_gb_widget_params/wp-json/gwolle-gb/[gwolle_gb][gwolle_gb_list]