
Nostr Verify Security & Risk Analysis
wordpress.org/plugins/nostr-verifyVerify yourself with Nostr, using NIP-05
Is Nostr Verify Safe to Use in 2026?
Generally Safe
Score 92/100Nostr Verify has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "nostr-verify" v1.2.0 plugin exhibits a very strong security posture based on the provided static analysis. The absence of any identified dangerous functions, raw SQL queries, file operations, or external HTTP requests is highly commendable. The plugin also demonstrates good output escaping practices with 94% of outputs properly escaped, and correctly utilizes nonce checks. The lack of known vulnerabilities in its history further reinforces this positive assessment.
However, the absence of any taint analysis results (total flows analyzed: 0) and a complete lack of capability checks are areas that warrant attention. While no direct risks are currently identified, these omissions mean that the plugin has not been rigorously tested for potential injection vulnerabilities that might arise from user-supplied data, nor does it implement robust access control for its (currently non-existent) entry points. The very small attack surface (0 entry points) is a significant strength that currently mitigates most theoretical risks, but a more comprehensive security review would benefit from exploring these areas.
In conclusion, the "nostr-verify" plugin appears to be built with security in mind, demonstrating excellent handling of common web vulnerabilities. The lack of historical vulnerabilities and the clean code signals are significant strengths. The primary area for improvement, though not a current risk due to the minimal attack surface, would be to incorporate taint analysis and capability checks to ensure a robust security foundation should the plugin's functionality or attack surface expand in the future.
Key Concerns
- Taint analysis not performed
- No capability checks
Nostr Verify Security Vulnerabilities
Nostr Verify Code Analysis
Output Escaping
Nostr Verify Attack Surface
WordPress Hooks 8
Maintenance & Trust
Nostr Verify Maintenance & Trust
Maintenance Signals
Community Trust
Nostr Verify Alternatives
WebFinger
webfinger
WebFinger for WordPress
host-meta
host-meta
host-meta for WordPress!
/well-known-uris/
well-known-uris
"Well-Known URIs" for WordPress!
Taboola
taboola
Use the Taboola plugin to generate revenue from native ads and drive engagement with editorial content.
JumpsuitAI – llms.txt + Markdown Endpoints
jumpsuitai-llms-txt
Generate /llms.txt, /llms-full.txt & .md endpoints for AI/LLMs in WordPress. Works with Yoast SEO, Rank Math, SEOPress & All in One SEO.
Nostr Verify Developer Profile
11 plugins · 2K total installs
How We Detect Nostr Verify
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
nostr-name-wrapnostr-pubkey-wrapnostr-name-descriptionnostr-key-descriptionname="nostr-name"id="nostr-name"name="nostr-key"id="nostr-key"aria-describedby="email-description"/.well-known/nostr.json