
Powie's WHOIS Domain Check Security & Risk Analysis
wordpress.org/plugins/powies-whoisCheck a Domain WHOIS Lookup for availability. Simple insert the [pwhois] shortcode on a page or post
Is Powie's WHOIS Domain Check Safe to Use in 2026?
Generally Safe
Score 92/100Powie's WHOIS Domain Check has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The 'powies-whois' plugin version 0.9.34 demonstrates several positive security practices, including a lack of dangerous functions, 100% use of prepared statements for SQL queries, and a relatively high percentage of properly escaped output. The absence of file operations and external HTTP requests further reduces its attack surface in those areas. Importantly, all identified entry points (AJAX handlers and shortcodes) appear to have some form of authentication or permission checks, and there are no detected taint flows indicating unsanitized paths.
However, the plugin does present some areas for concern. While the static analysis shows no explicit capability checks, the presence of a nonce check on one entry point is a good sign, but the lack of explicit capability checks on all entry points could still leave it vulnerable if permissions are not handled robustly at the WordPress core level. The plugin has a history of one known medium severity Cross-Site Scripting (XSS) vulnerability, which was last patched in 2020. Although currently unpatched CVEs are zero, the past XSS vulnerability suggests that input sanitization and output escaping, despite the current 88% rate, may require ongoing vigilance.
In conclusion, 'powies-whois' v0.9.34 has a generally good security posture due to its adherence to secure coding practices like prepared statements and the apparent protection of its entry points. The limited attack surface and lack of critical vulnerabilities in static analysis are strengths. Nevertheless, the past XSS vulnerability and the absence of explicit capability checks on all entry points warrant careful consideration and suggest that thorough testing and continuous monitoring remain important for this plugin.
Key Concerns
- Past medium XSS vulnerability
- No capability checks on entry points
- Some output not properly escaped
Powie's WHOIS Domain Check Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Power's WHOIS Domain Check <= 0.9.31 - Authenticated Stored Cross-Site Scripting
Powie's WHOIS Domain Check Release Timeline
Powie's WHOIS Domain Check Code Analysis
Output Escaping
Powie's WHOIS Domain Check Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
Powie's WHOIS Domain Check Maintenance & Trust
Maintenance Signals
Community Trust
Powie's WHOIS Domain Check Alternatives
WP24 Domain Check
wp24-domain-check
Check (whois) domain names for availability. Easy integration via shortcode or widget.
Domain Search for WHMCS
domain-search-for-whmcs
Integrate WHMCS domain search functionality into your WordPress website with a clean, responsive search form.
FAQ Schema
faq-schema
FAQ schema is an easy to use plugin which easily can add faq schema on your post, page or any other post type you just need to use a simple
Extended Shortcodes for Ultimate Membership Pro
extended-shortcodes-for-ultimate-membership-pro
Extend Ultimate Membership Pro functionality with a list of shortcodes which can be used by admin in order to manage content restriction.
DomainLabs Whois
domainlabs-whois
DomainLabs Domain Whois Plugin for Wordpress
Powie's WHOIS Domain Check Developer Profile
7 plugins · 660 total installs
How We Detect Powie's WHOIS Domain Check
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/powies-whois/pwhois.js/wp-content/plugins/powies-whois/pwhois.jsHTML / DOM Fingerprints
<!-- pWHOIS Plugin Output by www.powie.de --><!-- /pWHOIS Plugin Output --><!-- pwhois settings -->pWhoisAjax<form method="post" id="whois" action=""><input type="hidden" name="action" value="pwhois_post" /><legend><input type="text" size="30" name="domain" id="domain" />