
MintNFT Plugin Security & Risk Analysis
wordpress.org/plugins/mintnftThe “MintNFT Plugin” is a useful tool for those who want to mint their own NFTs without having to build an entire minting platform from scratch.
Is MintNFT Plugin Safe to Use in 2026?
Generally Safe
Score 92/100MintNFT Plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The mintnft plugin v1.1.0 presents a significant security risk due to its extensive unprotected AJAX handlers. With 28 AJAX handlers and none of them implementing authentication checks, any unauthenticated user can potentially trigger these functions, leading to a large attack surface. While the static analysis found no critical or high severity taint flows and SQL queries utilize prepared statements, the lack of capability checks and nonce verification on these numerous entry points is a major concern. The plugin also shows external HTTP requests, which could be exploited if not handled carefully. The absence of any recorded vulnerability history is positive, suggesting good development practices in the past, but it does not mitigate the immediate risks identified in the current code analysis. The plugin's strengths lie in its use of prepared statements for SQL and a majority of properly escaped output. However, these are overshadowed by the critical exposure of its AJAX functionality. A recommendation for immediate remediation is to implement proper authentication and authorization checks on all AJAX handlers.
Key Concerns
- 28 unprotected AJAX handlers
- 0 nonce checks on AJAX handlers
- 1 capability check on 28 entry points
- 79% properly escaped output
MintNFT Plugin Security Vulnerabilities
MintNFT Plugin Release Timeline
MintNFT Plugin Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
MintNFT Plugin Attack Surface
AJAX Handlers 28
WordPress Hooks 9
Maintenance & Trust
MintNFT Plugin Maintenance & Trust
Maintenance Signals
Community Trust
MintNFT Plugin Alternatives
Kredeum NFTs, the easiest way to sell your NFTs directly on your WordPress site
kredeum-nfts
Sell your NFTs directly on your WordPress site in an easy and fast way.
KoalaMint Plugin
koalamint
The No-Code Solution to Launch a Generative NFT Collection On your Website.
EthPress – Web3 Login
ethpress
EthPress Web3 Login Wordpress Plugin adds the capability to connect with cryptocurrency wallets such as MetaMask or WalletConnect QR code.
Ethereum Wallet
ethereum-wallet
The user friendly NFT and ERC20 tokens Ethereum Wallet with BSC and Polygon support for your WordPress site and WooCommerce store.
Token / NFT / Blockchain Page Gating
litprotocol-wp-lit-gated
Gate your content based on blockchain conditions like NFT ownership.
MintNFT Plugin Developer Profile
5 plugins · 20 total installs
How We Detect MintNFT Plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mintnft/assets/css/style.css/wp-content/plugins/mintnft/assets/js/main.js/wp-content/plugins/mintnft/assets/js/main.jsmintnft/assets/css/style.css?ver=mintnft/assets/js/main.js?ver=HTML / DOM Fingerprints
MintNFT_formNFTMintNFT_row_ServerTypeMintNFT_row_PinataKeypinata_dataMintNFT_row_PinataSecretMintNFT_row_getway_typeMintNFT_row_image_prefix+5 moredata-settings-savedMintNFT_option_name