
Konfirmi Plugin Security & Risk Analysis
wordpress.org/plugins/konfirmiKONFIRMI allows you to easily and automatically verify your customer's age, ID, address, and other information.
Is Konfirmi Plugin Safe to Use in 2026?
Generally Safe
Score 85/100Konfirmi Plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'konfirmi' plugin version 2.1.3 exhibits a mixed security posture. While the code signals are largely positive, with no dangerous functions, a reasonable percentage of SQL queries using prepared statements, and good output escaping, there are significant concerns regarding its attack surface and the lack of essential security checks.
The primary risks stem from two unprotected entry points: one AJAX handler and one REST API route, both lacking proper authentication and permission checks. This opens the door to potential unauthorized actions if these endpoints can be accessed by unauthenticated users. The absence of any nonce checks or capability checks further exacerbates this risk, suggesting a disregard for fundamental WordPress security practices.
Despite the clean vulnerability history with zero known CVEs, this does not negate the immediate risks identified in the static analysis. A lack of historical vulnerabilities can sometimes indicate a smaller user base or less rigorous security auditing in the past, rather than inherent robustness. The plugin's strengths lie in its avoidance of dangerous functions and its general approach to SQL and output handling. However, the identified unprotected entry points and the complete lack of capability and nonce checks represent critical weaknesses that need immediate attention to improve its overall security.
Key Concerns
- Unprotected AJAX handler
- Unprotected REST API route
- Missing nonce checks on AJAX
- Missing capability checks
- SQL queries not using prepared statements (3/8)
- Output escaping not properly implemented (18% of outputs)
Konfirmi Plugin Security Vulnerabilities
Konfirmi Plugin Code Analysis
SQL Query Safety
Output Escaping
Konfirmi Plugin Attack Surface
AJAX Handlers 1
REST API Routes 1
Shortcodes 1
WordPress Hooks 24
Maintenance & Trust
Konfirmi Plugin Maintenance & Trust
Maintenance Signals
Community Trust
Konfirmi Plugin Alternatives
Age Verification & Identity Verification by Token of Trust
token-of-trust
Verify age at checkout, protect pages from underage visitors, or set up advanced identity verification checks. Setup wizard gets you going in minutes.
Trust Swiftly — Identity Verification for WooCommerce
trust-swiftly-verification
The trusted flexible, secure, and accurate identity verification platform for WooCommerce.
BlueCheck – Age Verification
bluecheck-age-verification
Verify customer age at checkout. Cut fraud with photo ID verification. Check purchaser age info.
Identity Verification for WooCommerce
identity-verification-for-woocommerce
Eliminate fraud & verify customer age with real ID checks
Shuftipro KYC
shuftipro-kyc-identity-verification
Add Shuftipro identity verification process to WordPress websites.
Konfirmi Plugin Developer Profile
1 plugin · 10 total installs
How We Detect Konfirmi Plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/konfirmi/assets/css/konfirmi.min.css/wp-content/plugins/konfirmi/assets/js/Config.js/wp-content/plugins/konfirmi/assets/js/konfirmi.js/wp-content/plugins/konfirmi/assets/js/Base.js/wp-content/plugins/konfirmi/assets/js/agile-crm.js/wp-content/plugins/konfirmi/assets/js/caldera-form.js/wp-content/plugins/konfirmi/assets/js/Config.js/wp-content/plugins/konfirmi/assets/js/konfirmi.js/wp-content/plugins/konfirmi/assets/js/Base.js/wp-content/plugins/konfirmi/assets/js/agile-crm.js/wp-content/plugins/konfirmi/assets/js/caldera-form.jsHTML / DOM Fingerprints
Konfirmi/v1/widget/(?P<id>\d+)Konfirmi Widget