
LegalWeb Cloud Security & Risk Analysis
wordpress.org/plugins/legalweb-cloudWordPress Consent Management Platform (CMP) for GDPR/DSGVO compliance, imprint and privacy policy, powered by the legalweb.io cloud service.
Is LegalWeb Cloud Safe to Use in 2026?
Generally Safe
Score 99/100LegalWeb Cloud has a strong security track record. Known vulnerabilities have been patched promptly.
The "legalweb-cloud" plugin v1.1.8 presents a mixed security posture. On the positive side, there are no unprotected entry points (AJAX handlers, REST API routes) and a single nonce check is present, suggesting some foundational security awareness. However, significant concerns emerge from the static analysis, particularly the use of the `unserialize` function, which is inherently risky if not strictly controlled. Additionally, the SQL queries are not prepared, leaving them vulnerable to SQL injection attacks. The low percentage of properly escaped output (6%) is a critical red flag, indicating a high likelihood of Cross-Site Scripting (XSS) vulnerabilities across numerous output points.
The plugin has a history of one medium severity CVE, specifically related to Cross-Site Scripting, which was patched. While no current unpatched vulnerabilities exist, the pattern of XSS issues in the past, combined with the static analysis showing poor output escaping and unsanitized flows, suggests a recurring problem with input validation and output sanitization. The taint analysis, while not revealing critical or high severity issues, did identify unsanitized paths, which could be exploited in conjunction with the other weaknesses.
In conclusion, while the plugin has a clean recent vulnerability history and some basic security checks, the significant number of unescaped outputs, unsanitized paths, lack of prepared SQL statements, and the presence of `unserialize` create substantial security risks. These issues point to potential XSS and SQL injection vulnerabilities that require immediate attention and remediation.
Key Concerns
- Unescaped output is a critical risk
- Unsanitized paths found in taint analysis
- SQL queries without prepared statements
- Dangerous unserialize function used
- Medium severity XSS vulnerability in history
LegalWeb Cloud Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
LegalWeb Cloud <= 1.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
LegalWeb Cloud Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
LegalWeb Cloud Attack Surface
Shortcodes 9
WordPress Hooks 23
Maintenance & Trust
LegalWeb Cloud Maintenance & Trust
Maintenance Signals
Community Trust
LegalWeb Cloud Alternatives
AdSimple Cookie Consent Banner
adsimple-cookie-manager-for-wp
Add a GDPR-compliant cookie consent banner to your website. Certified CMP under IAB Europe TCF with CMP ID 463.
GDPR Cookie Compliance – Cookie Banner, Cookie Consent, Cookie Notice for CCPA, EU Cookie Law
gdpr-cookie-compliance
Cookie notice banner for GDPR, CCPA, EU cookie law, data protection and privacy regulations and other cookie law and consent notice requirements on yo …
CCM19 Integration
ccm19-integration
Integrates the CCM19 Cookie Consent Manager into WordPress. To use this plugin CCM19 needs to be bought or leased.
CookieHub – Cookie Consent Banner (DSGVO, CCPA, RGPD and GDPR compliance)
cookiehub
Take control effortlessly with CookieHub – GDPR-compliant solution for cookie management and compliance.
Cookie Notice & Consent
cookie-notice-consent
Display a cookie notice, collect consent for different categories and output scripts if consent is given.
LegalWeb Cloud Developer Profile
2 plugins · 10K total installs
How We Detect LegalWeb Cloud
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/legalweb-cloud/css/bootstrap.min.css/wp-content/plugins/legalweb-cloud/css/legalweb-cloud-admin.css/wp-content/plugins/legalweb-cloud/js/legalweb-cloud-admin.js/wp-content/plugins/legalweb-cloud/js/bootstrap.min.js/wp-content/plugins/legalweb-cloud/js/legalweb-cloud-admin.js/wp-content/plugins/legalweb-cloud/js/bootstrap.min.jslegalweb-cloud/css/bootstrap.min.css?ver=legalweb-cloud/css/legalweb-cloud-admin.css?ver=legalweb-cloud/js/legalweb-cloud-admin.js?ver=legalweb-cloud/js/bootstrap.min.js?ver=HTML / DOM Fingerprints
legalweb-cloud-admin-messagedata-message-idargs