
Age Verification & Identity Verification by Token of Trust Security & Risk Analysis
wordpress.org/plugins/token-of-trustVerify age at checkout, protect pages from underage visitors, or set up advanced identity verification checks. Setup wizard gets you going in minutes.
Is Age Verification & Identity Verification by Token of Trust Safe to Use in 2026?
Generally Safe
Score 100/100Age Verification & Identity Verification by Token of Trust has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'token-of-trust' plugin v3.32.2 exhibits a concerning security posture due to a significant number of unprotected entry points. While the plugin has no recorded vulnerability history, indicating a potentially low historical risk, the static analysis reveals several areas that warrant attention. Specifically, 6 out of 8 AJAX handlers and 1 out of 1 REST API route lack authentication checks, creating a substantial attack surface accessible to unauthenticated users. Furthermore, the taint analysis shows 6 flows with unsanitized paths, a critical indicator of potential vulnerabilities, even though they are not classified as critical or high severity in this specific scan. The moderate percentage of proper output escaping and the usage of prepared statements for SQL queries are positive signs, but the unescaped output and raw SQL queries still present a risk. The presence of bundled libraries like Guzzle and Select2 is standard, but their security depends on their individual patch status, which is not detailed here. Overall, the plugin's strengths lie in its lack of historical vulnerabilities and some good coding practices like prepared statements. However, the numerous unprotected entry points and unsanitized code paths are significant weaknesses that could be exploited.
Key Concerns
- AJAX handlers without auth checks
- REST API routes without permission callbacks
- Flows with unsanitized paths
- SQL queries not using prepared statements
- Output not properly escaped
- Nonce checks present
- Capability checks present
Age Verification & Identity Verification by Token of Trust Security Vulnerabilities
Age Verification & Identity Verification by Token of Trust Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Age Verification & Identity Verification by Token of Trust Attack Surface
AJAX Handlers 8
REST API Routes 1
Shortcodes 2
WordPress Hooks 124
Scheduled Events 2
Maintenance & Trust
Age Verification & Identity Verification by Token of Trust Maintenance & Trust
Maintenance Signals
Community Trust
Age Verification & Identity Verification by Token of Trust Alternatives
Didit Verify
didit-verify
Add identity verification to any WordPress page or WooCommerce checkout using Didit.
Konfirmi Plugin
konfirmi
KONFIRMI allows you to easily and automatically verify your customer's age, ID, address, and other information.
iDenfy for WooCommerce
idenfy-for-woocommerce
Add identity verification to your WooCommerce store. Verify customers before checkout with ID checks — powered by iDenfy.
Age Gate
age-gate
A plugin to check the age of a visitor before view site or specified content
Age Gate Lite
age-gate-lite
A lightweight, customisable age gate to lock content from younger audience.
Age Verification & Identity Verification by Token of Trust Developer Profile
1 plugin · 50 total installs
How We Detect Age Verification & Identity Verification by Token of Trust
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/token-of-trust/token-of-trust.css/wp-content/plugins/token-of-trust/token-of-trust.js/wp-content/plugins/token-of-trust/Modules/Shared/Assets/tot-error-log.js/wp-content/plugins/token-of-trust/analytics/build/analyticsTracker.bundle.js/wp-content/plugins/token-of-trust/admin/plugin-deactivation/assets/scripts/plugin-deactivation.js/wp-content/plugins/token-of-trust/token-of-trust.js/wp-content/plugins/token-of-trust/Modules/Shared/Assets/tot-error-log.js/wp-content/plugins/token-of-trust/analytics/build/analyticsTracker.bundle.js/wp-content/plugins/token-of-trust/admin/plugin-deactivation/assets/scripts/plugin-deactivation.jstoken-of-trust.css?ver=token-of-trust.js?ver=tot-error-log.js?ver=analyticsTracker.bundle.js?ver=plugin-deactivation.js?ver=HTML / DOM Fingerprints
tot-taxes-noticedata-tot-hostdata-tot-versiondata-tot-app-domaindata-tot-rest-urldata-tot-noncedata-tot-app-user-email+1 moretotObjtotPluginDeactivationData/wp-json/tot/v1/webhooks/wp-json/tot/v1/client-api/verify-person