
WP DSGVO Tools (GDPR) Security & Risk Analysis
wordpress.org/plugins/shapepress-dsgvoWP DSGVO Tools (GDPR) by legalweb.io help you to fulfill the GDPR (DSGVO) compliance guidance (GDPR)
Is WP DSGVO Tools (GDPR) Safe to Use in 2026?
Generally Safe
Score 90/100WP DSGVO Tools (GDPR) has a strong security track record. Known vulnerabilities have been patched promptly.
The shapepress-dsgvo plugin v3.1.38 exhibits a mixed security posture. While it demonstrates good practices in output escaping and has a relatively low percentage of raw SQL queries, several concerning indicators are present. The presence of a single unprotected REST API route represents a direct attack vector. Furthermore, the taint analysis revealing two high-severity flows with unsanitized paths is a significant concern, suggesting potential for injection vulnerabilities. The plugin's history of 5 known CVEs, including two high-severity ones and a recent (though seemingly patched) vulnerability, indicates a pattern of past security weaknesses. The presence of the `unserialize` function also raises flags, as it can be a source of critical vulnerabilities if not handled with extreme care.
Despite these concerns, the plugin does show strengths such as a high percentage of properly escaped output, a good use of prepared statements for SQL queries, and the presence of nonce and capability checks, albeit limited in number. The bundled TCPDF library is a known entity, and its specific version should be checked for any known exploits, though it's not flagged as a direct issue in the provided data.
In conclusion, while the plugin has made efforts towards secure coding, the identified unprotected REST API endpoint, high-severity taint flows, and historical CVEs warrant careful consideration. The plugin is not without risk, and ongoing vigilance regarding its security is recommended. Further investigation into the specific nature of the unsanitized paths and the REST API route is crucial.
Key Concerns
- Unprotected REST API route
- High severity taint flows
- Dangerous function: unserialize
- Bundled outdated library (TCPDF v6.4.4)
- Historical high severity vulnerabilities
WP DSGVO Tools (GDPR) Security Vulnerabilities
CVEs by Year
Severity Breakdown
5 total CVEs
WP DSGVO Tools (GDPR) <= 3.1.36 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'lw_content_block' Shortcode
WP DSGVO Tools (GDPR) <= 3.1.32 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
WP DSGVO Tools (GDPR) <= 3.1.23 - Unauthenticated Stored Cross-Site Scripting
WP DSGVO Tools (GDPR) <= 3.1.23 - Unauthenticated Arbitrary Post Deletion
WP DSGVO Tools (GDPR) <= 2.2.18 - Cross-Site Scripting
WP DSGVO Tools (GDPR) Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
WP DSGVO Tools (GDPR) Attack Surface
REST API Routes 1
Shortcodes 9
WordPress Hooks 55
Maintenance & Trust
WP DSGVO Tools (GDPR) Maintenance & Trust
Maintenance Signals
Community Trust
WP DSGVO Tools (GDPR) Alternatives
AWEOS YouTube load per click
aweos-youtube-iframe-load-per-click
This Plugin prevents the auto loading from YouTube iframes. It will be loaded after the user permits it.
iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more
iubenda-cookie-law-solution
The solution for GDPR compliance + more. Get your cookie banner, privacy policy, terms and conditions and handle cookie consent in just one plugin.
TermsFeed AutoTerms: Privacy Policy Generator, Cookie Consent, GDPR, CCPA, Terms & Conditions, Disclaimers, Cookies Policy, EULA
auto-terms-of-service-and-privacy-policy
All-in-One compliance solution from TermsFeed: Generator of Privacy Policy, T&Cs, Affiliate Disclaimers and Cookie Consent Notice Banner.
DSGVO All in one for WP
dsgvo-all-in-one-for-wp
An All in One GDPR Plugin for everything! Responsive Cookie Notice - Imprint & Privacy Policy Generator - integrate external Services GDPR complia …
Legal Pages – Privacy Policy, Terms & Conditions, GDPR, CCPA, and Cookie Notice Generator
legal-pages
The best WordPress legal pages generator that comes with pre-made templates for GDPR, CCPA, DMCA, Privacy Policy, Terms & Conditions, Cookie Polic …
WP DSGVO Tools (GDPR) Developer Profile
2 plugins · 10K total installs
How We Detect WP DSGVO Tools (GDPR)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/shapepress-dsgvo/public/css/style.css/wp-content/plugins/shapepress-dsgvo/public/js/build/frontend.js/wp-content/plugins/shapepress-dsgvo/public/js/build/backend.js/wp-content/plugins/shapepress-dsgvo/admin/css/admin.css/wp-content/plugins/shapepress-dsgvo/public/js/build/frontend.js/wp-content/plugins/shapepress-dsgvo/public/js/build/backend.jsshapepress-dsgvo/public/css/style.css?ver=shapepress-dsgvo/public/js/build/frontend.js?ver=shapepress-dsgvo/public/js/build/backend.js?ver=shapepress-dsgvo/admin/css/admin.css?ver=HTML / DOM Fingerprints
sp-dsgvo-cookie-bannersp-dsgvo-headlinesp-dsgvo-settingssp-dsgvo-cookie-settingsspdsgvo-noticespdsgvo-notice-blockspdsgvo-gdpr-wrapperdata-sp-dsgvo-typedata-sp-dsgvo-idSPDSGVO