
Terms of Service & Privacy Policy Generator Security & Risk Analysis
wordpress.org/plugins/terms-of-service-and-privacy-policyGenerates "Terms Of Service" and "Privacy Policy" texts based on your information using shortcodes.
Is Terms of Service & Privacy Policy Generator Safe to Use in 2026?
Use With Caution
Score 63/100Terms of Service & Privacy Policy Generator has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The plugin "terms-of-service-and-privacy-policy" v1.0 exhibits a mixed security posture. On the positive side, the static analysis shows no dangerous functions, no file operations, and all SQL queries utilize prepared statements, indicating good practices in these areas. The limited attack surface with only two shortcodes, neither of which appear to be unprotected, is also a strength. However, a significant concern is the low percentage of properly escaped output (18%), which presents a substantial risk of Cross-Site Scripting (XSS) vulnerabilities, especially given the plugin's history of such issues.
Taint analysis reveals no identified flows, which is positive, but this could also be due to the limited scope or complexity of the plugin's code that was analyzed. The absence of nonce checks and a low number of capability checks (only 1 identified) across the entry points, despite the identified shortcodes, suggests a potential for authorization bypass issues or insecure handling of user-provided data.
The plugin has a documented history of one medium-severity CVE, specifically related to Cross-Site Scripting, which is currently unpatched and dated in the future (August 2025). This historical pattern, coupled with the low output escaping rate in static analysis, strongly suggests that XSS is a recurring and significant threat. While the plugin demonstrates strengths in database and file handling, the prevalent output escaping deficiency and the unpatched XSS vulnerability are critical weaknesses that require immediate attention to mitigate security risks.
Key Concerns
- Unpatched CVE (medium severity)
- Low percentage of properly escaped output (18%)
- Lack of nonce checks on entry points
- Low number of capability checks on entry points
Terms of Service & Privacy Policy Generator Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Terms of Service & Privacy Policy Generator <= 1.0 - Authenticated (Administrator+) Stored Cross-Site Scripting
Terms of Service & Privacy Policy Generator Code Analysis
Output Escaping
Terms of Service & Privacy Policy Generator Attack Surface
Shortcodes 2
WordPress Hooks 3
Maintenance & Trust
Terms of Service & Privacy Policy Generator Maintenance & Trust
Maintenance Signals
Community Trust
Terms of Service & Privacy Policy Generator Alternatives
WP Terms Popup – Terms and Conditions and Privacy Policy WordPress Popups
wp-terms-popup
Use WP Terms Popup to ask visitors to agree to your terms and conditions or privacy policy before they are allowed to view your site.
Signature Add-On for WooCommerce
woocommerce-digital-signature
Automatically require your WooCommerce customers to sign a legally binding contract before downloading your product. Easy to Use.
WPGear – Consent Privacy Policy Acceptance
wpgear-consent-privacy-policy-acceptance
Requests the website visitor to confirm consent to the use of personal data (Privacy Policy) and the storage of cookies on first visit.
iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more
iubenda-cookie-law-solution
The solution for GDPR compliance + more. Get your cookie banner, privacy policy, terms and conditions and handle cookie consent in just one plugin.
TermsFeed AutoTerms: Privacy Policy Generator, Cookie Consent, GDPR, CCPA, Terms & Conditions, Disclaimers, Cookies Policy, EULA
auto-terms-of-service-and-privacy-policy
All-in-One compliance solution from TermsFeed: Generator of Privacy Policy, T&Cs, Affiliate Disclaimers and Cookie Consent Notice Banner.
Terms of Service & Privacy Policy Generator Developer Profile
1 plugin · 700 total installs
How We Detect Terms of Service & Privacy Policy Generator
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
wrapnav-tab-wrappernav-tabnav-tab-activetab-contentmanage-menusform-tableid="wl_tos-wp"name="wl_tos_tos_heading"name="wl_tos_pp_heading"name="wl_tos_name"name="wl_tos_full_name"name="wl_tos_possessive_name"+10 more[wl_tos][wl_privacypolicy]