
NoSSL – protect your website Security & Risk Analysis
wordpress.org/plugins/nossl-protect-your-websiteNoSSL encrypts the logins and all forms of your WordPress.
Is NoSSL – protect your website Safe to Use in 2026?
Generally Safe
Score 85/100NoSSL – protect your website has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'nossl-protect-your-website' plugin v1.1 exhibits a mixed security posture. On the positive side, it demonstrates no known CVEs, a clean vulnerability history, and no external HTTP requests, indicating a generally stable and low-profile plugin. The absence of AJAX handlers, REST API routes, shortcodes, and cron events, coupled with the fact that all SQL queries use prepared statements, significantly limits its attack surface and direct database manipulation risks.
However, the static analysis reveals several concerning code signals. The presence of dangerous functions like `set_time_limit`, `unserialize`, `ini_set`, and `create_function` without any apparent authorization or capability checks presents potential risks. `unserialize` is particularly concerning as it can lead to Remote Code Execution (RCE) if used with untrusted input. The low percentage of properly escaped output (9%) suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities, where malicious scripts could be injected and executed in the user's browser.
While the plugin has a clean vulnerability history, this can be misleading. The lack of detected issues might stem from a lack of in-depth analysis or testing rather than inherent security. The combination of dangerous functions and poor output sanitization, without any nonce or capability checks, creates a significant potential for exploitation. Therefore, despite its clean history, the plugin has inherent risks that require attention.
Key Concerns
- Dangerous function: unserialize without checks
- Dangerous function: create_function without checks
- Dangerous function: ini_set without checks
- Dangerous function: set_time_limit without checks
- Low percentage of properly escaped output
- No nonce checks
- No capability checks
NoSSL – protect your website Security Vulnerabilities
NoSSL – protect your website Release Timeline
NoSSL – protect your website Code Analysis
Dangerous Functions Found
Output Escaping
NoSSL – protect your website Attack Surface
WordPress Hooks 3
Maintenance & Trust
NoSSL – protect your website Maintenance & Trust
Maintenance Signals
Community Trust
NoSSL – protect your website Alternatives
Formular af CitizenOne journalsystem
formular-af-citizenone-journalsystem
Embed customizable contact forms from CitizenOne on any WordPress site.
Open One On Demand Delivery
open-one-on-demand-delivery
Open One On Demand Delivery is used to link a store developed in WooCommerce with the Open One API and in this way have a delivery system connected to …
Sanremo Trails
sanremo-trails
Here is a short description of the plugin. This should be no more than 150 characters. No markup here.
NoSSL – protect your website Developer Profile
1 plugin · 10 total installs
How We Detect NoSSL – protect your website
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/nossl-protect-your-website/nossl/style/nossl.css/wp-content/plugins/nossl-protect-your-website/nossl/javascript/nossl_start.min.js/wp-content/plugins/nossl-protect-your-website/nossl/javascript/nossl_start.min.jsnossl-style?ver=nossl-js?ver=HTML / DOM Fingerprints
########################################################################################## NoSSL V1.1 - Encryption between browser and server########################################################################################## Copyright (C) 2013 - 2014 Smart In Media GmbH & Co. KG+6 more