
Shuftipro KYC Security & Risk Analysis
wordpress.org/plugins/shuftipro-kyc-identity-verificationAdd Shuftipro identity verification process to WordPress websites.
Is Shuftipro KYC Safe to Use in 2026?
Generally Safe
Score 92/100Shuftipro KYC has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The shuftipro-kyc-identity-verification plugin version 1.1.6 exhibits a generally strong security posture based on the provided static analysis. The plugin demonstrates excellent practices by utilizing prepared statements for all SQL queries and ensuring a high percentage of output is properly escaped, significantly mitigating common risks like SQL injection and cross-site scripting. The absence of known CVEs and a clean vulnerability history further reinforces this positive outlook, indicating a well-maintained and secure plugin over time. However, several critical areas warrant attention. The complete lack of nonce checks and capability checks across its entry points, particularly the single shortcode, represents a significant security weakness. This means that any user, regardless of their role or permissions, could potentially trigger the shortcode's functionality, leading to unauthorized actions or information disclosure. While no critical taint flows were identified, the absence of these checks on core entry points could inadvertently enable them. The presence of an external HTTP request also introduces a potential vector for information leakage or reliance on an insecure external service, though this risk is mitigated by the lack of identified vulnerabilities.
Key Concerns
- Missing nonce checks on entry points
- Missing capability checks on entry points
- Potential for unescaped output (5% unescaped)
- External HTTP requests present
Shuftipro KYC Security Vulnerabilities
Shuftipro KYC Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Shuftipro KYC Attack Surface
Shortcodes 1
WordPress Hooks 6
Maintenance & Trust
Shuftipro KYC Maintenance & Trust
Maintenance Signals
Community Trust
Shuftipro KYC Alternatives
24TT Document Verifier
24tt-document-verifier
The 24TT Document Verifier is a powerful, enterprise-grade solution designed for institutions, universities, businesses, and government bodies globall …
Identity Verification for WooCommerce
identity-verification-for-woocommerce
Eliminate fraud & verify customer age with real ID checks
advertSAFE Site Seal
advertsafe
Add trust to your website and users with the advertSAFE site seal plugin. Plus earn 25% commission from any new member sign ups through your seal.
AwareID – Biometric Identity Authentication
awareid-wc-integration
Secure app logins without passwords, facilitate trusted transactions & reduce chargebacks by enabling easy biometric enrollment & authentication.
Konfirmi Plugin
konfirmi
KONFIRMI allows you to easily and automatically verify your customer's age, ID, address, and other information.
Shuftipro KYC Developer Profile
1 plugin · 40 total installs
How We Detect Shuftipro KYC
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/shuftipro-kyc-identity-verification/admin/css/shuftipro-kyc-admin.css/wp-content/plugins/shuftipro-kyc-identity-verification/admin/js/shuftipro-kyc-admin.js/wp-content/plugins/shuftipro-kyc-identity-verification/admin/js/jquery.validate.min.js/wp-content/plugins/shuftipro-kyc-identity-verification/admin/js/shuftipro-kyc-admin.js/wp-content/plugins/shuftipro-kyc-identity-verification/admin/js/jquery.validate.min.jsshuftipro-kyc-identity-verification/admin/js/shuftipro-kyc-admin.js?ver=shuftipro-kyc-identity-verification/admin/js/jquery.validate.min.js?ver=