
Janolaw AGB Hosting Security & Risk Analysis
wordpress.org/plugins/janolaw-agb-hostingThis plugin gets legal documents provided by janolaw AG (commercial service) like General terms, Imprint etc. for Wordpress sites and WooCommerce shop …
Is Janolaw AGB Hosting Safe to Use in 2026?
Generally Safe
Score 100/100Janolaw AGB Hosting has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The janolaw-agb-hosting plugin v4.4.13 presents a mixed security posture. On the positive side, it demonstrates good practices by not utilizing dangerous functions, employing prepared statements for all SQL queries, and having no known historical vulnerabilities. The absence of critical or high-severity taint flows is also a strong indicator of careful coding. However, there are significant concerns regarding output escaping, with 100% of outputs being unescaped. This could lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is directly rendered without sanitization. Additionally, the plugin has a relatively large attack surface of 20 shortcodes, and while the static analysis indicates no unprotected entry points, the sheer number of shortcodes warrants careful review of their internal implementations for potential logic flaws or vulnerabilities that might not be caught by static analysis alone. The presence of file operations and external HTTP requests, while not inherently problematic, should be monitored for secure implementation.
The lack of historical vulnerabilities is a positive sign, suggesting the developers may have a good understanding of security principles or that the plugin's functionality hasn't historically attracted attacks. Nevertheless, the critical issue of unescaped output remains a substantial risk. The plugin's strengths lie in its clean SQL handling and lack of known security incidents. The primary weakness is the widespread failure to escape output, which is a fundamental security requirement and a common vector for attacks. Further investigation into the shortcode implementations is also recommended.
Key Concerns
- 100% of outputs are unescaped
- Large attack surface (20 shortcodes)
- 0 Nonce checks on entry points
Janolaw AGB Hosting Security Vulnerabilities
Janolaw AGB Hosting Code Analysis
Output Escaping
Janolaw AGB Hosting Attack Surface
Shortcodes 20
WordPress Hooks 5
Maintenance & Trust
Janolaw AGB Hosting Maintenance & Trust
Maintenance Signals
Community Trust
Janolaw AGB Hosting Alternatives
Legal Text Connector of the IT-Recht Kanzlei
legal-texts-connector-it-recht-kanzlei
Ensures that your website is always provided with warning-proof legal texts from IT-Recht Kanzlei after booking the GTC service.
getLaw WP API Client
getlaw-wp-api-client
With this Plugin you can automatically embed legal texts of the Legal-Tech-Platform www.getLaw.de in your website and your shop.
wpShopGermany IT-RECHT KANZLEI
wpshopgermany-it-recht-kanzlei
Mit Hilfe dieses Plugins ist es möglich deutsche rechtssichere Texte (für Shops) über eine API zu aktualisieren.
Haendlerbund API
haendlerbund-api
API Connector to Händlerbund HB legal - to get legal text from your account
wpShopGermany – Händlerbund
wpshopgermany-handlerbund
Mit Hilfe dieses Plugins ist es möglich deutsche rechtssichere Texte (für Shops) zu aktualisieren. Die Texte werden vom Händlerbund bezogen.
Janolaw AGB Hosting Developer Profile
1 plugin · 1K total installs
How We Detect Janolaw AGB Hosting
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/janolaw-agb-hosting/js/janolaw-agb-hosting.js/wp-content/plugins/janolaw-agb-hosting/css/janolaw-agb-hosting.css/wp-content/plugins/janolaw-agb-hosting/js/janolaw-agb-hosting.jsjanolaw-agb-hosting/js/janolaw-agb-hosting.js?ver=janolaw-agb-hosting/css/janolaw-agb-hosting.css?ver=HTML / DOM Fingerprints
janolaw-agb-hosting-wrapper<!-- janolaw agb hosting --><!-- janolaw agb hosting ENDE -->janolaw_agb_hosting_params[janolaw_agb][janolaw_impressum][janolaw_widerrufsbelehrung][janolaw_widerrufsformular]