
IT-Recht Kanzlei Trust-Widget Security & Risk Analysis
wordpress.org/plugins/it-recht-kanzlei-trustwidgetDas Trust-Widget der IT-Recht Kanzlei für Onlineshops mit Wordpress. Mehr Kundenvertrauen durch zwei vertrauensbildende Maßnahmen in einem Widget.
Is IT-Recht Kanzlei Trust-Widget Safe to Use in 2026?
Generally Safe
Score 100/100IT-Recht Kanzlei Trust-Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "it-recht-kanzlei-trustwidget" plugin exhibits a generally strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events suggests a very limited attack surface. Furthermore, the plugin utilizes prepared statements for all its SQL queries, which is a crucial security best practice to prevent SQL injection vulnerabilities. The lack of any discovered dangerous functions, file operations, or external HTTP requests further contributes to its perceived safety.
However, there are a few areas that warrant attention. Approximately 33% of the plugin's output is not properly escaped, which could open the door to Cross-Site Scripting (XSS) vulnerabilities if the unescaped data originates from untrusted user input. The complete absence of nonce checks and capability checks, especially in conjunction with the identified unescaped output, raises a significant concern. While the current attack surface is zero, if any functionality were to be added that involved user interaction or modification of data, the lack of these fundamental security mechanisms would present a serious risk. The plugin's vulnerability history is clean, with no recorded CVEs, which is positive. However, the lack of historical data makes it difficult to assess long-term security trends or the developer's track record in addressing security issues. In conclusion, the plugin is built on a solid foundation with good SQL handling, but the unescaped output and the absence of nonce and capability checks are notable weaknesses that could be exploited if the plugin's functionality evolves or if unforeseen entry points are introduced.
Key Concerns
- Unescaped output detected
- No nonce checks
- No capability checks
IT-Recht Kanzlei Trust-Widget Security Vulnerabilities
IT-Recht Kanzlei Trust-Widget Code Analysis
Output Escaping
IT-Recht Kanzlei Trust-Widget Attack Surface
WordPress Hooks 5
Maintenance & Trust
IT-Recht Kanzlei Trust-Widget Maintenance & Trust
Maintenance Signals
Community Trust
IT-Recht Kanzlei Trust-Widget Alternatives
Full Trust
full-trust
Show reviews, stores, branches, badges, media coverage, metrics, social profiles, awards, certificates, payment methods and more all in one place
Classic Widgets
classic-widgets
Enables the previous "classic" widgets settings screens in Appearance - Widgets and the Customizer. Disables the block editor from managing widgets.
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor
elementskit-lite
Join millions who empower their websites with ElementsKit Elementor Addons. Get templates, & 100+ widgets like header-footer, mega menu, custom widget
Essential Addons for Elementor – Popular Elementor Templates & Widgets
essential-addons-for-elementor-lite
Elementor addon offering 110+ widgets and templates — Elementor Gallery, Slider, Form, Post Grid, Menu, Accordion, WooCommerce & more.
Ultimate Addons for Elementor
header-footer-elementor
Powerful Elementor addon with advanced Elementor widgets, templates, WooCommerce widgets & Header-Footer builder to build professional websites fa …
IT-Recht Kanzlei Trust-Widget Developer Profile
2 plugins · 10K total installs
How We Detect IT-Recht Kanzlei Trust-Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/it-recht-kanzlei-trustwidget/css/admin-styles.csshttps://www.it-recht-kanzlei.de/trustwidget/HTML / DOM Fingerprints
itrk-settings-pageitrk-banneritrk-logoitrk-support-boxitrk-hiddendata-it-recht-kanzlei-trustwidget-settings