oik-privacy-policy Security & Risk Analysis

wordpress.org/plugins/oik-privacy-policy

Generate a privacy policy page, compliant with UK cookie law (EU cookie directive) for use on your website

800 active installs v1.4.11 PHP + WP 4.9.8+ Updated Nov 4, 2025
eu-cookie-directiveoikprivacy-policyuk-cookie-law
99
A · Safe
CVEs total1
Unpatched0
Last CVEAug 6, 2025
Safety Verdict

Is oik-privacy-policy Safe to Use in 2026?

Generally Safe

Score 99/100

oik-privacy-policy has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Aug 6, 2025Updated 5mo ago
Risk Assessment

The static analysis of oik-privacy-policy v1.4.11 reveals a generally positive security posture with no identified dangerous functions, SQL injection vulnerabilities, file operations, or external HTTP requests. The complete absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface. However, a concerning aspect is the 0 capability checks and 0 nonce checks, which indicate a lack of essential security measures for any potential entry points, even if none were explicitly identified in this analysis. This suggests that if new entry points are introduced or if the current ones are missed, they might be left unprotected.

The vulnerability history shows one past medium severity vulnerability related to Cross-site Scripting, which was last patched in August 2025. While there are no currently unpatched vulnerabilities, this past incident highlights a potential weakness in input sanitization. The 60% proper output escaping is also a concern, implying that 40% of outputs might be susceptible to cross-site scripting if they handle user-supplied data, though the taint analysis did not reveal any issues in this specific version.

In conclusion, while the current version of oik-privacy-policy appears to have a minimal attack surface and no exploitable vulnerabilities in its static analysis, the lack of capability and nonce checks is a significant oversight. The past XSS vulnerability and the imperfect output escaping rate warrant caution. The plugin's strength lies in its limited functionality and lack of direct dangerous code, but its weakness stems from the absence of fundamental security checks that could protect against unforeseen vulnerabilities or future changes.

Key Concerns

  • No capability checks found
  • No nonce checks found
  • Incomplete output escaping (40%)
  • Past medium severity vulnerability (XSS)
Vulnerabilities
1

oik-privacy-policy Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-52743medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

oik-privacy-policy <= 1.4.10 - Reflected Cross-Site Scripting

Aug 6, 2025 Patched in 1.4.11 (94d)
Code Analysis
Analyzed Mar 16, 2026

oik-privacy-policy Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
3 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

60% escaped5 total outputs
Attack Surface

oik-privacy-policy Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionafter_plugin_row_oik-privacy-policy/oik-privacy-policy.phpoik-privacy-policy.php:59
actionoik_admin_menuoik-privacy-policy.php:72
actionadmin_noticesoik-privacy-policy.php:73
Maintenance & Trust

oik-privacy-policy Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 4, 2025
PHP min version
Downloads74K

Community Trust

Rating80/100
Number of ratings2
Active installs800
Developer Profile

oik-privacy-policy Developer Profile

bobbingwide

16 plugins · 7K total installs

92
trust score
Avg Security Score
97/100
Avg Patch Time
15 days
View full developer profile
Detection Fingerprints

How We Detect oik-privacy-policy

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/oik-privacy-policy/css/oik-privacy-policy.css/wp-content/plugins/oik-privacy-policy/js/oik-privacy-policy.js
Script Paths
/wp-content/plugins/oik-privacy-policy/js/oik-privacy-policy.js
Version Parameters
oik-privacy-policy/css/oik-privacy-policy.css?ver=oik-privacy-policy/js/oik-privacy-policy.js?ver=

HTML / DOM Fingerprints

CSS Classes
oik-privacy-policy-admin
HTML Comments
Copyright Bobbing Wide 2012-2017, 2023, 2024, 2025Note: Checkboxes don't need validatingand there's little point validating the text since we allow (X)HTML and shortcodesAND if the user chooses to change a list start field to something else+11 more
Data Attributes
data-oik-privacy-policy-introdata-oik-privacy-policy-effdatedata-oik-privacy-policy-wecollectdata-oik-privacy-policy-weusedata-oik-privacy-policy-sharetwothirddata-oik-privacy-policy-thirdparty+6 more
JS Globals
oik_privacy_policy_admin
Shortcode Output
[oik-privacy-policy]
FAQ

Frequently Asked Questions about oik-privacy-policy