Usercentrics Privacy Policy Generator Security & Risk Analysis

wordpress.org/plugins/privacy-policy-usercentrics

Generate GDPR, CCPA & global privacy and cookie policies automatically. Stay compliant, build trust, and save time with Usercentrics.

100 active installs v1.0.1 PHP 7.4+ WP 6.0+ Updated Feb 27, 2026
ccpacompliancegdprprivacyprivacy-policy
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Usercentrics Privacy Policy Generator Safe to Use in 2026?

Generally Safe

Score 100/100

Usercentrics Privacy Policy Generator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "privacy-policy-usercentrics" plugin v1.0.1 exhibits a generally positive security posture, with a strong emphasis on security best practices. The complete absence of known CVEs and the high percentage of properly escaped outputs (98%) are significant strengths. Furthermore, the plugin correctly implements nonce and capability checks for all its AJAX entry points, and there are no directly exploitable paths identified in the taint analysis. The absence of shortcodes, cron events, and REST API routes also limits the potential attack surface.

However, a critical concern arises from the presence of a single SQL query that does not utilize prepared statements. While the overall volume of SQL queries is low, this unescaped query represents a potential vulnerability to SQL injection, especially if the data originates from user input. Additionally, the plugin performs external HTTP requests, which, while not inherently a vulnerability, can introduce risks if the endpoints are compromised or if sensitive data is transmitted insecurely.

In conclusion, the plugin is well-secured in most aspects, demonstrating good development practices. The primary weakness lies in the unparameterized SQL query. Addressing this specific area would significantly enhance the plugin's security, complementing its otherwise robust security features. The lack of historical vulnerabilities is a positive indicator of consistent secure development.

Key Concerns

  • SQL query not using prepared statements
Vulnerabilities
None known

Usercentrics Privacy Policy Generator Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Usercentrics Privacy Policy Generator Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
4
161 escaped
Nonce Checks
6
Capability Checks
4
File Operations
0
External Requests
2
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

98% escaped165 total outputs
Data Flows
6 unsanitized

Data Flow Analysis

6 flows6 with unsanitized paths
ajaxValidatePolicyId (src\Admin\Actions\PolicyActions.php:64)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Usercentrics Privacy Policy Generator Attack Surface

Entry Points4
Unprotected0

AJAX Handlers 4

authwp_ajax_ppguc_validate_policy_idsrc\Admin\Actions\PolicyActions.php:56
authwp_ajax_ppguc_dismiss_bannersrc\Admin\BannerDismissHandler.php:25
authwp_ajax_ppguc_install_pluginsrc\Admin\Controllers\AddonsController.php:61
authwp_ajax_ppguc_activate_pluginsrc\Admin\Controllers\AddonsController.php:62
WordPress Hooks 26
actionplugins_loadedprivacy-policy-usercentrics.php:54
filterscript_loader_tagsrc\Admin\AssetsManager.php:93
filterscript_loader_tagsrc\Admin\AssetsManager.php:144
filterscript_loader_tagsrc\Admin\AssetsManager.php:207
filterscript_loader_tagsrc\Admin\AssetsManager.php:235
actionupdate_option_ppguc_usercentrics_display_pagesrc\Admin\EditorContent.php:61
actionadmin_enqueue_scriptssrc\Admin\EditorContent.php:64
actionadd_meta_boxessrc\Admin\EditorContent.php:67
actionsave_post_pagesrc\Admin\EditorContent.php:70
filterredirect_post_locationsrc\Admin\EditorContent.php:73
filteradmin_body_classsrc\Admin\EditorContent.php:238
actionadmin_footersrc\Admin\EditorContent.php:247
actionadmin_noticessrc\Admin\MainMenu.php:92
actionadmin_enqueue_scriptssrc\Admin\MainMenu.php:195
actionadmin_noticessrc\Admin\NoticeHandler.php:30
actionadmin_noticessrc\Admin\NoticeHandler.php:31
actionadmin_footersrc\Admin\NoticeHandler.php:32
actionadmin_initsrc\Core\Plugin.php:145
actionadmin_menusrc\Core\Plugin.php:146
actionadmin_initsrc\Core\Plugin.php:147
actionadmin_initsrc\Core\Plugin.php:148
actionadmin_enqueue_scriptssrc\Core\Plugin.php:149
actionadmin_enqueue_scriptssrc\Core\Plugin.php:150
actioninitsrc\Core\Plugin.php:162
filterthe_contentsrc\Frontend\PolicyContent.php:58
actionwp_enqueue_scriptssrc\Frontend\PolicyContent.php:61
Maintenance & Trust

Usercentrics Privacy Policy Generator Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 27, 2026
PHP min version7.4
Downloads824

Community Trust

Rating0/100
Number of ratings0
Active installs100
Developer Profile

Usercentrics Privacy Policy Generator Developer Profile

cookiebot

2 plugins · 100K total installs

69
trust score
Avg Security Score
86/100
Avg Patch Time
413 days
View full developer profile
Detection Fingerprints

How We Detect Usercentrics Privacy Policy Generator

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/privacy-policy-usercentrics/assets/dist/css/admin-styles.css/wp-content/plugins/privacy-policy-usercentrics/assets/dist/js/settings.js/wp-content/plugins/privacy-policy-usercentrics/assets/dist/js/toast.js/wp-content/plugins/privacy-policy-usercentrics/assets/dist/js/video-lazy-load.js/wp-content/plugins/privacy-policy-usercentrics/assets/dist/js/status-banner.js/wp-content/plugins/privacy-policy-usercentrics/assets/dist/js/addons.js/wp-content/plugins/privacy-policy-usercentrics/assets/dist/js/support.js
Script Paths
/privacy-policy-usercentrics/assets/dist/js/settings.js/privacy-policy-usercentrics/assets/dist/js/toast.js/privacy-policy-usercentrics/assets/dist/js/video-lazy-load.js/privacy-policy-usercentrics/assets/dist/js/status-banner.js/privacy-policy-usercentrics/assets/dist/js/addons.js/privacy-policy-usercentrics/assets/dist/js/support.js
Version Parameters
privacy-policy-usercentrics/assets/dist/css/admin-styles.css?ver=privacy-policy-usercentrics/assets/dist/js/settings.js?ver=privacy-policy-usercentrics/assets/dist/js/toast.js?ver=privacy-policy-usercentrics/assets/dist/js/video-lazy-load.js?ver=privacy-policy-usercentrics/assets/dist/js/status-banner.js?ver=privacy-policy-usercentrics/assets/dist/js/addons.js?ver=privacy-policy-usercentrics/assets/dist/js/support.js?ver=

HTML / DOM Fingerprints

CSS Classes
wp-menu-image
HTML Comments
Plugin Name: Usercentrics Privacy Policy GeneratorPlugin URI: https://usercentrics.com/privacy-policy-generatorDescription: Easily integrate Usercentrics privacy policies. No manual script insertion required.Version: 1.0.1+42 more
Data Attributes
type="module"
JS Globals
ppgucStringsppgucAjaxppgucBanner
FAQ

Frequently Asked Questions about Usercentrics Privacy Policy Generator