
NexaGuard CMP Security & Risk Analysis
wordpress.org/plugins/nexaguard-cmpConsent Management Platform for WordPress. Inject NexaGuard loader, enable Google Consent Mode v2, and manage/reset consent via a simple admin UI.
Is NexaGuard CMP Safe to Use in 2026?
Generally Safe
Score 100/100NexaGuard CMP has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The nexaguard-cmp plugin v0.2.3 exhibits a generally strong security posture, with several positive indicators. The absence of dangerous functions, file operations, and external HTTP requests is commendable. All SQL queries are properly prepared, and a high percentage of outputs are escaped, significantly reducing the risk of common web vulnerabilities like SQL injection and Cross-Site Scripting (XSS). The presence of nonce and capability checks further bolsters its defenses against unauthorized actions.
However, a notable concern is the presence of a REST API route without a permission callback. This means that this endpoint is accessible and executable without proper authorization, potentially exposing sensitive functionality or data to unauthenticated users. While the static analysis and taint analysis did not reveal any specific critical or high-severity flaws, this unprotected REST API route represents a tangible attack vector that should be addressed. The plugin's vulnerability history is clean, with no recorded CVEs, which suggests a diligent development approach to security so far, but this does not negate the identified issue.
In conclusion, nexaguard-cmp v0.2.3 is well-developed from a security standpoint, but the unprotected REST API route is a significant weakness that lowers its overall security score. Addressing this specific entry point is crucial to improving its security posture and mitigating potential risks.
Key Concerns
- REST API route without permission callback
NexaGuard CMP Security Vulnerabilities
NexaGuard CMP Code Analysis
Output Escaping
NexaGuard CMP Attack Surface
REST API Routes 1
Shortcodes 2
WordPress Hooks 17
Maintenance & Trust
NexaGuard CMP Maintenance & Trust
Maintenance Signals
Community Trust
NexaGuard CMP Alternatives
Consensu.io | Conformidade e Consentimento de Cookies para LGPD
consensu-io
Configure facilmente consentimento e monitoramento de cookies em seu website e esteja em conformidade com a LGPD.
Cookiefy GDPR Compliance
cookiefy
GDPR-compliant cookie consent management with automatic cookie detection and intelligent classification.
GDPR-Extensions-com – Consent Manager
gdpr-consent-manager
Short Description: Ensure GDPR compliance effortlessly. Scan for cookies, resources, and security issues. Generate reports.
Cookie Notice & Compliance for GDPR / CCPA
cookie-notice
Cookie Notice allows you to you elegantly inform users that your site uses cookies and helps you comply with GDPR, CCPA and other data privacy laws.
WP Consent API
wp-consent-api
Simple Consent API to read and register the current consent category.
NexaGuard CMP Developer Profile
1 plugin · 0 total installs
How We Detect NexaGuard CMP
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/nexaguard-cmp/assets/css/admin.css/wp-content/plugins/nexaguard-cmp/assets/js/admin.jsnexaguard-cmp/assets/css/admin.css?ver=nexaguard-cmp/assets/js/admin.js?ver=HTML / DOM Fingerprints
nexaguard-adminnexaguard-containernexaguard-heronexaguard-hero__eyebrownexaguard-hero__titlenexaguard-hero__subtitlenexaguard-hero__actionsnexaguard-btn+11 morenexaguard_debug_nexaguard