
OpenPGP Form Encryption for WordPress Security & Risk Analysis
wordpress.org/plugins/openpgp-form-encryptionOpenPGP public key encryption for any textarea with a shortcode button.
Is OpenPGP Form Encryption for WordPress Safe to Use in 2026?
Generally Safe
Score 91/100OpenPGP Form Encryption for WordPress has a strong security track record. Known vulnerabilities have been patched promptly.
The openpgp-form-encryption plugin version 1.5.1 presents a generally good security posture with no identified critical or high severity vulnerabilities in the static analysis. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests are all positive indicators. The plugin also demonstrates good practices by utilizing prepared statements for all its SQL queries and having a high percentage of properly escaped output. However, there are still areas for concern.
The static analysis reveals a potential risk due to the presence of one shortcode, which acts as an entry point to the plugin. While the analysis states there are no unprotected entry points, the lack of explicit mention of capability checks or nonce checks for this shortcode is a weakness. The vulnerability history shows one past medium severity CVE related to Cross-Site Scripting, which, while patched, indicates a historical tendency for input sanitization issues. The recent nature of this CVE (June 2024) suggests that developers should remain vigilant.
In conclusion, the plugin has strong foundational security practices in place. The primary concern is the potential for subtle vulnerabilities within the shortcode's implementation that might not have been caught by the static analysis, especially given the past XSS vulnerability. While the current version appears secure based on the provided data, ongoing vigilance and thorough testing of shortcode functionalities are recommended.
Key Concerns
- Past medium CVE (XSS)
- Shortcode as potential entry point without explicit checks
- 1 of 5 outputs not properly escaped
OpenPGP Form Encryption for WordPress Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
OpenPGP Form Encryption for WordPress <= 1.5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
OpenPGP Form Encryption for WordPress Code Analysis
Output Escaping
OpenPGP Form Encryption for WordPress Attack Surface
Shortcodes 1
WordPress Hooks 2
Maintenance & Trust
OpenPGP Form Encryption for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
OpenPGP Form Encryption for WordPress Alternatives
PGP Key Generator
pgp-key-generator
A plugin to generate private and public PGP keys. No need to install any software to encrypt and decrypt PGP messages.
WP PGP Encrypted Emails
wp-pgp-encrypted-emails
Signs and encrypts emails using PGP/GPG keys or X.509 certificates. Provides OpenPGP and S/MIME functions via WordPress plugin API.
wp2pgpmail
wp2pgpmail
A simple PGP Mail Form Plugin. Enter your PGP public key, then visitors will be able to send you PGP encrypted messages by mail from a form.
Secure Encrypted Form
secure-encrypted-form
This plugin adds a secure form in your website that uses OpenPGP encryption to secure sensitive communications.
WP jCryption Security
wp-jcryption
Prevents forms data against sniffing network traffic through encryption provided by jCryption javascript library.
OpenPGP Form Encryption for WordPress Developer Profile
2 plugins · 40 total installs
How We Detect OpenPGP Form Encryption for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/openpgp-form-encryption/js/init.js/wp-content/plugins/openpgp-form-encryption/js/openpgp.worker.2.6.1.min.js/wp-content/plugins/openpgp-form-encryption/js/openpgp.2.6.1.min.jsjs/openpgp.2.6.1.min.jsjs/init.jsjs/openpgp.worker.2.6.1.min.jsopenpgp.2.6.1.min.jsHTML / DOM Fingerprints
cryptbuttondata-textarea-iddata-pubkey-uriopenpgpWorkerUri<button type="button" id="cryptbutton" class="cryptbuttondata-pubkey-uri="data-textarea-id="